| Index: chrome/browser/ui/cocoa/tabs/tab_strip_controller.mm
|
| diff --git a/chrome/browser/ui/cocoa/tabs/tab_strip_controller.mm b/chrome/browser/ui/cocoa/tabs/tab_strip_controller.mm
|
| index 5d008da722bc20cfaadfd16f1f942e5c2d2dfcdb..2df953314fb0bd30b483c4ac749cb3c5094dbb76 100644
|
| --- a/chrome/browser/ui/cocoa/tabs/tab_strip_controller.mm
|
| +++ b/chrome/browser/ui/cocoa/tabs/tab_strip_controller.mm
|
| @@ -2059,6 +2059,10 @@ CGFloat FlipXInView(NSView* view, CGFloat width, CGFloat x) {
|
| }
|
|
|
| - (void)openURL:(GURL*)url inView:(NSView*)view at:(NSPoint)point {
|
| + // Security: Block JavaScript to prevent self-XSS.
|
| + if (url->SchemeIs(url::kJavaScriptScheme))
|
| + return;
|
| +
|
| // Get the index and disposition.
|
| NSInteger index;
|
| WindowOpenDisposition disposition;
|
|
|