Index: content/renderer/pepper/pepper_video_decoder_host.cc |
diff --git a/content/renderer/pepper/pepper_video_decoder_host.cc b/content/renderer/pepper/pepper_video_decoder_host.cc |
index 4fc2d2c8b6e480fd887ea4a1a1a5dc41d76fe712..139058535495d20e3e06c932a494edc7f43f4b9c 100644 |
--- a/content/renderer/pepper/pepper_video_decoder_host.cc |
+++ b/content/renderer/pepper/pepper_video_decoder_host.cc |
@@ -313,6 +313,8 @@ void PepperVideoDecoderHost::ProvidePictureBuffers( |
} |
void PepperVideoDecoderHost::PictureReady(const media::Picture& picture) { |
+ // So far picture.visible_rect is not used. If used, visible_rect should |
+ // be validated since it comes from GPU process and may not be trustworthy. |
host()->SendUnsolicitedReply( |
pp_resource(), |
PpapiPluginMsg_VideoDecoder_PictureReady(picture.bitstream_buffer_id(), |