<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>29100</bug_id>
          
          <creation_ts>2015-08-29 10:45:53 +0000</creation_ts>
          <short_desc>Current iframe sandbox does not prevent download from sandboxed child frame</short_desc>
          <delta_ts>2016-04-28 16:12:16 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>HTML WG</product>
          <component>CR HTML5 spec</component>
          <version>unspecified</version>
          <rep_platform>PC</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>MOVED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>s.h.h.n.j.k</reporter>
          <assigned_to name="Robin Berjon">robin</assigned_to>
          <cc>lwatson</cc>
    
    <cc>public-html-admin</cc>
          
          <qa_contact name="HTML WG Bugzilla archive list">public-html-bugzilla</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>122894</commentid>
    <comment_count>0</comment_count>
      <attachid>1622</attachid>
    <who name="">s.h.h.n.j.k</who>
    <bug_when>2015-08-29 10:45:53 +0000</bug_when>
    <thetext>Created attachment 1622
Please let me know if it does not work

Hi,

Current iframe sandbox does not prevent download from sandboxed child frame. This allows malicious ads to force download malicious files which users might think that it is served from trusted parent domain.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>122915</commentid>
    <comment_count>1</comment_count>
    <who name="">s.h.h.n.j.k</who>
    <bug_when>2015-08-31 09:38:28 +0000</bug_when>
    <thetext>Is there anyone looking into this?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>126273</commentid>
    <comment_count>2</comment_count>
    <who name="Léonie Watson">lwatson</who>
    <bug_when>2016-04-28 16:12:16 +0000</bug_when>
    <thetext>Moved to HTML on Github:
https://github.com/w3c/html/issues/301</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>1622</attachid>
            <date>2015-08-29 10:45:53 +0000</date>
            <delta_ts>2015-08-29 10:45:53 +0000</delta_ts>
            <desc>Please let me know if it does not work</desc>
            <filename>iframe.html</filename>
            <type>text/html</type>
            <size>535</size>
            <attacher>s.h.h.n.j.k</attacher>
            
              <data encoding="base64">77u/PCFET0NUWVBFIGh0bWwgUFVCTElDICItLy9XM0MvL0RURCBYSFRNTCAxLjAgVHJhbnNpdGlv
bmFsLy9FTiIgImh0dHA6Ly93d3cudzMub3JnL1RSL3hodG1sMS9EVEQveGh0bWwxLXRyYW5zaXRp
b25hbC5kdGQiPg0KPGh0bWwgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGh0bWwiPg0K
PGhlYWQ+DQo8L2hlYWQ+DQo8Ym9keT4NCjxpZnJhbWUgc2FuZGJveCBzcmM9Imh0dHBzOi8vd3d3
Lmdvb2dsZS5jb20vcz9zY2xpZW50PXBzeS1hYiZzaXRlPSZzb3VyY2U9aHAmcT10ZXN0Jm9xPSZn
c19sPSZwYng9MSZiYXY9b24uMixvci5yX2NwLiZidm09YnYuMTAxNTI1MTg4LGQuZDI0JmZwPWI5
ZDcyMWE2ZGU1NDllNjkmYml3PTEzNjYmYmloPTE1MCZkcHI9MSZwZj1wJmdzX3JuPTY0JmdzX3Jp
PXBzeS1hYiZ0b2s9c1hJZ2s4TkRhU3gtYW1oWEdEeERYZyZjcD00JmdzX2lkPWRqJnhocj10JnRj
aD0xJmVjaD01JnBzaT1pNHZoVmE2ZE44ZmRVY2ItcnZBUC4xNDQwODQ0Njg0MTA2LjEiPjwvaWZy
YW1lPg0KPC9ib2R5Pg0KPC9odG1sPg==
</data>

          </attachment>
      

    </bug>

</bugzilla>