github web-platform-tests/wpt merge_pr_46476

latest releases: merge_pr_49470, epochs/three_hourly/2024-12-03_06H, epochs/six_hourly/2024-12-03_06H...
16 months ago

[PEPC] Fix PEPC text being displaceable via CSS pseudo selectors

This fixes an exploit that uses the ::before CSS pseudo-selector that
displaces the text in the permission element and replaces it with
content chosen by the author. The added test is modeled after the
exploit.

Fixed: 342355738
Change-Id: Id2f05a9febe3d2f97662065d5c1a46a6ade260f3
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/5563204
Commit-Queue: Andy Paicu andypaicu@chromium.org
Reviewed-by: Rune Lillesveen futhark@chromium.org
Cr-Commit-Position: refs/heads/main@{#1305684}

Don't miss a new wpt release

NewReleases is sending notifications on new releases.