Fix openInNewWindow scheme deny-list bypass in bookmarkManagerPrivate [chromium/src : main]

0 views
Skip to first unread message

Zhuoyu Qian (Gerrit)

unread,
Jun 25, 2026, 11:48:04 AM (12 hours ago) Jun 25
to John Lee, Chromium LUCI CQ, chromium...@chromium.org, chromium-a...@chromium.org, extension...@chromium.org
Attention needed from John Lee

Zhuoyu Qian added 1 comment

Patchset-level comments
File-level comment, Patchset 1 (Latest):
Zhuoyu Qian . resolved

Hi John,
Please have a look at this change, thanks!

Open in Gerrit

Related details

Attention is currently required from:
  • John Lee
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement is not satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I23cd53c34673c049933bd332ffc9d3bd442341fa
Gerrit-Change-Number: 8001415
Gerrit-PatchSet: 1
Gerrit-Owner: Zhuoyu Qian <zhuoy...@microsoft.com>
Gerrit-Reviewer: John Lee <john...@chromium.org>
Gerrit-Reviewer: Zhuoyu Qian <zhuoy...@microsoft.com>
Gerrit-Attention: John Lee <john...@chromium.org>
Gerrit-Comment-Date: Thu, 25 Jun 2026 15:47:31 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
satisfied_requirement
unsatisfied_requirement
open
diffy

John Lee (Gerrit)

unread,
Jun 25, 2026, 4:09:21 PM (8 hours ago) Jun 25
to Zhuoyu Qian, John Lee, Chromium LUCI CQ, chromium...@chromium.org, chromium-a...@chromium.org, extension...@chromium.org
Attention needed from Zhuoyu Qian

John Lee voted Code-Review+1

Code-Review+1
Open in Gerrit

Related details

Attention is currently required from:
  • Zhuoyu Qian
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement satisfiedCode-Owners
  • requirement satisfiedCode-Review
  • requirement satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I23cd53c34673c049933bd332ffc9d3bd442341fa
Gerrit-Change-Number: 8001415
Gerrit-PatchSet: 1
Gerrit-Owner: Zhuoyu Qian <zhuoy...@microsoft.com>
Gerrit-Reviewer: John Lee <john...@chromium.org>
Gerrit-Reviewer: Zhuoyu Qian <zhuoy...@microsoft.com>
Gerrit-Attention: Zhuoyu Qian <zhuoy...@microsoft.com>
Gerrit-Comment-Date: Thu, 25 Jun 2026 20:09:06 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: Yes
satisfied_requirement
open
diffy

Zhuoyu Qian (Gerrit)

unread,
Jun 25, 2026, 9:18:57 PM (3 hours ago) Jun 25
to John Lee, Chromium LUCI CQ, chromium...@chromium.org, chromium-a...@chromium.org, extension...@chromium.org

Zhuoyu Qian voted Commit-Queue+2

Commit-Queue+2
Open in Gerrit

Related details

Attention set is empty
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement satisfiedCode-Owners
  • requirement satisfiedCode-Review
  • requirement satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I23cd53c34673c049933bd332ffc9d3bd442341fa
Gerrit-Change-Number: 8001415
Gerrit-PatchSet: 1
Gerrit-Owner: Zhuoyu Qian <zhuoy...@microsoft.com>
Gerrit-Reviewer: John Lee <john...@chromium.org>
Gerrit-Reviewer: Zhuoyu Qian <zhuoy...@microsoft.com>
Gerrit-Comment-Date: Fri, 26 Jun 2026 01:18:24 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: Yes
satisfied_requirement
open
diffy

Chromium LUCI CQ (Gerrit)

unread,
Jun 25, 2026, 9:32:41 PM (3 hours ago) Jun 25
to Zhuoyu Qian, John Lee, chromium...@chromium.org, chromium-a...@chromium.org, extension...@chromium.org

Chromium LUCI CQ submitted the change

Change information

Commit message:
Fix openInNewWindow scheme deny-list bypass in bookmarkManagerPrivate

BookmarkManagerPrivateOpenInNewWindowFunction::RunOnReady passed
bookmark node URLs straight to Navigate() without the
ExtensionTabUtil::PrepareURLForNavigation scheme deny-list that the
sibling openInNewTab path applies to the same data. A compromised
bookmarks WebUI renderer could stage a devtools://, chrome-untrusted://,
or javascript: URL via bookmarks.create and open it as a
browser-initiated top-level window.

Route every bookmark URL through PrepareURLForNavigation before
navigating, and use the prepared URL for both the incognito filtering
and the navigation. Add a regression test covering denied schemes.
Change-Id: I23cd53c34673c049933bd332ffc9d3bd442341fa
Reviewed-by: John Lee <john...@chromium.org>
Commit-Queue: Zhuoyu Qian <zhuoy...@microsoft.com>
Cr-Commit-Position: refs/heads/main@{#1652858}
Files:
  • M chrome/browser/extensions/api/bookmark_manager_private/bookmark_manager_private_api.cc
  • M chrome/browser/extensions/api/bookmark_manager_private/bookmark_manager_private_api_browsertest.cc
Change size: M
Delta: 2 files changed, 57 insertions(+), 14 deletions(-)
Branch: refs/heads/main
Submit Requirements:
  • requirement satisfiedCode-Review: +1 by John Lee
Open in Gerrit
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: merged
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I23cd53c34673c049933bd332ffc9d3bd442341fa
Gerrit-Change-Number: 8001415
Gerrit-PatchSet: 2
Gerrit-Owner: Zhuoyu Qian <zhuoy...@microsoft.com>
Gerrit-Reviewer: Chromium LUCI CQ <chromiu...@luci-project-accounts.iam.gserviceaccount.com>
Gerrit-Reviewer: John Lee <john...@chromium.org>
Gerrit-Reviewer: Zhuoyu Qian <zhuoy...@microsoft.com>
open
diffy
satisfied_requirement
Reply all
Reply to author
Forward
0 new messages