Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(608)

Unified Diff: chrome/android/java/src/org/chromium/chrome/browser/JavascriptAppModalDialog.java

Issue 11728004: Fix use after free in JavascriptAppModalDialogAndroid. (Closed) Base URL: svn://svn.chromium.org/chrome/trunk/src
Patch Set: Add missing 'virtual' (only needed by the Chromium style Clang plugin) Created 7 years, 12 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « no previous file | chrome/browser/ui/android/javascript_app_modal_dialog_android.h » ('j') | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: chrome/android/java/src/org/chromium/chrome/browser/JavascriptAppModalDialog.java
diff --git a/chrome/android/java/src/org/chromium/chrome/browser/JavascriptAppModalDialog.java b/chrome/android/java/src/org/chromium/chrome/browser/JavascriptAppModalDialog.java
index a400543db0997cd3c0c4742048fefe89710f3969..7d064abd4e30069d9c1f54572d479905e9f923bb 100644
--- a/chrome/android/java/src/org/chromium/chrome/browser/JavascriptAppModalDialog.java
+++ b/chrome/android/java/src/org/chromium/chrome/browser/JavascriptAppModalDialog.java
@@ -122,6 +122,7 @@ public class JavascriptAppModalDialog implements DialogInterface.OnClickListener
@CalledByNative
void dismiss() {
mDialog.dismiss();
+ mNativeDialogPointer = 0;
}
/**
@@ -175,11 +176,15 @@ public class JavascriptAppModalDialog implements DialogInterface.OnClickListener
}
public void confirm(String promptResult, boolean suppressDialogs) {
- nativeDidAcceptAppModalDialog(mNativeDialogPointer, promptResult, suppressDialogs);
+ if (mNativeDialogPointer != 0) {
+ nativeDidAcceptAppModalDialog(mNativeDialogPointer, promptResult, suppressDialogs);
+ }
}
public void cancel(boolean suppressDialogs) {
- nativeDidCancelAppModalDialog(mNativeDialogPointer, suppressDialogs);
+ if (mNativeDialogPointer != 0) {
+ nativeDidCancelAppModalDialog(mNativeDialogPointer, suppressDialogs);
+ }
}
private static class JavascriptAppAlertDialog extends JavascriptAppModalDialog {
« no previous file with comments | « no previous file | chrome/browser/ui/android/javascript_app_modal_dialog_android.h » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698