Skip to content

Commit f5056d0

Browse files
steimelchromemibrunin
authored andcommitted
[Backport] CVE-2021-30508: Heap buffer overflow in Media Feeds
Manual backport of patch originally reviewed on https://chromium-review.googlesource.com/c/chromium/src/+/2847504: Media Feeds: Disable Media Feeds and related features in M90 Media Feeds is deleted in M91 and later and is unused in previous versions as well. There is a security issue with Media Feeds though, so we'd like to force it to be disabled in previous versions, so this CL turns it off for M90. Bug: 1195340 Change-Id: I29e18be2abe4c1b4560d6324af3b6da93a97d947 Reviewed-by: dpapad <[email protected]> Reviewed-by: Frank Liberato <[email protected]> Commit-Queue: Tommy Steimel <[email protected]> Cr-Commit-Position: refs/branch-heads/4430@{#1389} Cr-Branched-From: e5ce7dc4f7518237b3d9bb93cccca35d25216cbe-refs/heads/master@{#857950} Reviewed-by: Allan Sandfeld Jensen <[email protected]>
1 parent 5b2293c commit f5056d0

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

chromium/media/base/media_switches.cc

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -730,15 +730,15 @@ const base::Feature kMediaEngagementHTTPSOnly{
730730

731731
// Enables Media Feeds to allow sites to provide specific recommendations for
732732
// users.
733-
const base::Feature kMediaFeeds{"MediaFeeds", base::FEATURE_ENABLED_BY_DEFAULT};
733+
const base::Feature kMediaFeeds{"MediaFeeds", base::FEATURE_DISABLED_BY_DEFAULT};
734734

735735
// Enables fetching Media Feeds periodically in the background.
736736
const base::Feature kMediaFeedsBackgroundFetching{
737-
"MediaFeedsBackgroundFetching", base::FEATURE_ENABLED_BY_DEFAULT};
737+
"MediaFeedsBackgroundFetching", base::FEATURE_DISABLED_BY_DEFAULT};
738738

739739
// Enables checking Media Feeds against safe search to prevent adult content.
740740
const base::Feature kMediaFeedsSafeSearch{"MediaFeedsSafeSearch",
741-
base::FEATURE_ENABLED_BY_DEFAULT};
741+
base::FEATURE_DISABLED_BY_DEFAULT};
742742

743743
// Send events to devtools rather than to chrome://media-internals
744744
const base::Feature kMediaInspectorLogging{"MediaInspectorLogging",

0 commit comments

Comments
 (0)