commit | d1a8cbeec4d9f9520a4bb1f4db6d3f62900ee709 | [log] [tgz] |
---|---|---|
author | elawrence <elawrence@chromium.org> | Wed Sep 14 18:38:43 2016 |
committer | Commit bot <commit-bot@chromium.org> | Wed Sep 14 18:42:30 2016 |
tree | 88028c84a2a7d57d6bfb6a4a98d1faf37a5c6037 | |
parent | 628a0b386bc8728a79e58934dbb14503e8cb0611 [diff] |
Ignore Javascript urls dropped on tabs When a Javascript: url is dropped on a tab, it executes in the security context of the selected tab, representing a script injection attack ("Dropjacking"). We will match other browsers and disallow such drops. BUG=639750 Review-Url: https://codereview.chromium.org/2323273003 Cr-Commit-Position: refs/heads/master@{#418620}