Hi everyone,

I'm removing a Blink exemption 
<https://crrev.com/c/8391502?forceReload=true> that permitted custom cursors 
<https://developer.mozilla.org/en-US/docs/Web/CSS/Reference/Properties/cursor> 
≤32x32 pixels to extend beyond the visual viewport. This applies Blink's 
existing bounds enforcement and next-specified-cursor fallback to ensure 
that custom cursors of any size fit entirely within the visual viewport.

Closing this security loophole protects users from malicious spoofing of 
browser UI, matches Safari's current behavior, and aligns with broader 
efforts to harden usable security. I will also ping the corresponding Firefox 
issue <https://bugzilla.mozilla.org/1804816>. We may explore future 
accommodations to improve gaming immersion 
<https://groups.google.com/a/chromium.org/g/blink-dev/c/HHpVKEBcYH8/m/mCRJIeIQAgAJ>,
 
and appreciate feedback from users and developers.

Thanks,
Mike

-- 
You received this message because you are subscribed to the Google Groups 
"blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/chromium.org/d/msgid/blink-dev/f69592a4-d76d-473a-a0fb-42408e5a18cfn%40chromium.org.

Reply via email to