-
@tunetheweb @jaffathecake @Benjamin_Aster @ChromiumDev The popup is browser UI, which can be spoofed. I suggested we rotate the site permission icon as a "line of death" replacement on mobile and desktop when interacting with the real prompt. One (weak-ish) attack vector was spoofed revoke prompts that only seemingly revoke access.