Hi everyone, I'm removing a Blink exemption <https://crrev.com/c/8391502?forceReload=true> that permitted custom cursors <https://developer.mozilla.org/en-US/docs/Web/CSS/Reference/Properties/cursor> ≤32x32 pixels to extend beyond the visual viewport. This applies Blink's existing bounds enforcement and next-specified-cursor fallback to ensure that custom cursors of any size fit entirely within the visual viewport.
Closing this security loophole protects users from malicious spoofing of browser UI, matches Safari's current behavior, and aligns with broader efforts to harden usable security. I will also ping the corresponding Firefox issue <https://bugzilla.mozilla.org/1804816>. We may explore future accommodations to improve gaming immersion <https://groups.google.com/a/chromium.org/g/blink-dev/c/HHpVKEBcYH8/m/mCRJIeIQAgAJ>, and appreciate feedback from users and developers. Thanks, Mike -- You received this message because you are subscribed to the Google Groups "blink-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/chromium.org/d/msgid/blink-dev/f69592a4-d76d-473a-a0fb-42408e5a18cfn%40chromium.org.
