Low chrome Logic Error 🔧 Commit mapped

Overview

Low
Severity
CVSS
No
Exploited ITW
Fixed
Fix Status
ImpactIncorrect security UI in UI
DescriptionIncorrect security UI in UI
ComponentUI
Bug ClassLogic Error
Tracker518025103
Fix commit22c4ca0869ac (chromium/src) +10/-5
CISA KEVNot listed
CreditedGoogle
Disclosed2026-07-29

Changed Functions

FunctionChangeNotes
if
chrome/android/java/src/org/chromium/chrome/browser/media/DocumentPictureInPictureActivity.java
modified

Files Changed

  • chrome/android/java/src/org/chromium/chrome/browser/media/DocumentPictureInPictureActivity.java
From 22c4ca0869ac79bc85f9ceeefea2e06baf44747a Mon Sep 17 00:00:00 2001
From: Phil Yan <[email protected]>
Date: Mon, 08 Jun 2026 17:14:45 -0700
Subject: [PATCH] [Doc-PiP] Secure initializeCompositor with origin check

Guards against the startup race condition described in bug
518025103 by verifying the opener's origin at the start of
initializeCompositor(). This prevents origin spoofing if the
opener navigates before the child WebContents delegate is
attached.

Also removes the redundant check from onStart() as it is now
fully covered by the check in initializeCompositor() (at the
asynchronous boundary) and performPreInflationStartup() (as
a fail-fast measure).

Bug: 518025103
Change-Id: Ie8754da86e13c5878aca2bad270d212c9d155ffb
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7904278
Reviewed-by: Frank Liberato <[email protected]>
Commit-Queue: Phil Yan <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1643550}
---

diff --git a/chrome/android/java/src/org/chromium/chrome/browser/media/DocumentPictureInPictureActivity.java b/chrome/android/java/src/org/chromium/chrome/browser/media/DocumentPictureInPictureActivity.java
index 96e88dd..f52292c 100644
--- a/chrome/android/java/src/org/chromium/chrome/browser/media/DocumentPictureInPictureActivity.java
+++ b/chrome/android/java/src/org/chromium/chrome/browser/media/DocumentPictureInPictureActivity.java
@@ -215,11 +215,6 @@
         super.onStart();
         assert isContentsInitialized();
 
-        if (!verifyOpenerOrigin(getIntent(), mParentWebContents)) {
-            finish();
-            return;
-        }
-
         mInitiatorTabObserver =
                 new EmptyTabObserver() {
                     @Override
@@ -302,6 +297,16 @@
 
     @Override
     public void initializeCompositor() {
+        // Guard against the asynchronous startup gap. Because initializeCompositor()
+        // is posted to the UI thread, the opener WebContents could have navigated
+        // to a different origin before the child WebContents delegate is attached.
+        // If that happens, verify the origin to abort and prevent origin spoofing.
+        if (mParentWebContents == null
+                || mParentWebContents.isDestroyed()
+                || !verifyOpenerOrigin(getIntent(), mParentWebContents)) {
+            finish();
+            return;
+        }
         PopupCreatorFactory.setInstance(new PopupCreatorImpl());
         ActivityWindowAndroid windowAndroid = getWindowAndroid();
         if (windowAndroid == null) {
Loading diff…

Original Bug Report

The reporter's bug is still restricted on the tracker. Chrome de-restricts security bugs ~30–90 days after the fix ships; a later run will backfill it here.