diff --git a/patches/chromium/.patches b/patches/chromium/.patches index 0cb73c91941a5..e019a86a684e6 100644 --- a/patches/chromium/.patches +++ b/patches/chromium/.patches @@ -128,3 +128,4 @@ fix_allow_ime_to_insert_zero-length_composition_string.patch fix_handling_non_client_pointer_events_from_pen_on_windows_10.patch backport_1063177.patch backport_1065122.patch +backport_1074317.patch diff --git a/patches/chromium/backport_1074317.patch b/patches/chromium/backport_1074317.patch new file mode 100644 index 0000000000000..31a33dfe3f07d --- /dev/null +++ b/patches/chromium/backport_1074317.patch @@ -0,0 +1,89 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Cheng Zhao +Date: Thu, 4 Oct 2018 14:57:02 -0700 +Subject: fix: stop leaking cross-origin post-redirect data using StackTrace + +[1074317] [High] [CVE-2020-6511]: Security: The CSP reports and stacktraces of errors leaks post-redirect URL for