Index: extensions/renderer/resources/guest_view/guest_view_container.js |
diff --git a/extensions/renderer/resources/guest_view/guest_view_container.js b/extensions/renderer/resources/guest_view/guest_view_container.js |
index efec02adb3a64303096e849bd0ec5888fa71499a..f34283160e7bcfc9f5a80d656dd364365f533957 100644 |
--- a/extensions/renderer/resources/guest_view/guest_view_container.js |
+++ b/extensions/renderer/resources/guest_view/guest_view_container.js |
@@ -33,6 +33,8 @@ function GuestViewContainer(element, viewType) { |
// Prevent GuestViewContainer inadvertently inheriting code from the global |
// Object, allowing a pathway for executing unintended user code execution. |
+// TODO(wjmaclean): Use utils.expose() here instead? Track down other issues |
+// of Object inheritance. https://crbug.com/701034 |
GuestViewContainer.prototype.__proto__ = null; |
// Forward public API methods from |proto| to their internal implementations. |