-
Bug
-
Resolution: Unresolved
-
Not Evaluated
-
None
-
6.9.0
-
None
Please add a feature to disable the availability of the web developer tools regardless of the environment varaibles or command line arguments.
In our opinion, this allows an attacker to subvertly change either the system environment variables or the command line arguments of Windows shortcuts and thereby enabling the remote developer tools without the user knowing about the attacker listening in or modifying the web communication.
We realize that an attacker who is able to change these configurations, is also able to do much worse, but most attacks require more knowlege and finesse, whereas this is a very open door.
We would like to programatically instruct the web engine globally to not open any ports for remote inspection.
- relates to
-
QTBUG-128292 Add option to disable deploying the qtwebengine_devtools_resources.pak
-
- Reported
-