You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
(this issue is from the review I did as part of PING's HR review)
It seems like you could communicate cross frames easily using takePhoto to set PhotoSettings in one frame, and then reading those settings back in another frame with getPhotoSettings. This weakens the privacy goals generally being pursed through site isolation, and would allow for cross site tracking.
The text was updated successfully, but these errors were encountered:
(this issue is from the review I did as part of PING's HR review)
It seems like you could communicate cross frames easily using takePhoto to set
PhotoSettings
in one frame, and then reading those settings back in another frame withgetPhotoSettings
. This weakens the privacy goals generally being pursed through site isolation, and would allow for cross site tracking.The text was updated successfully, but these errors were encountered: