Skip to content

[EyeDropper] Restrict API access to content area #428

Open
@krgovind

Description

[Writing on behalf of Chrome Security and Privacy teams. CC\ @camillelamy ]

The explainer states this as a goal:

Provide access to the color values of one or more user-selected pixels, including pixels rendered by different origins, or outside of the browser.

However, it is preferable to restrict API access only to the page content area only. Access to the browser window/controls area, or area outside of the browser could make clickjacking attacks possible; and potentially reveal fingerprintable information about the user (e.g. OS preferences).

Metadata

Labels

EyeDropperIssues relating to the EyeDropper API

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions