Google Chrome Bug: ERR_BLOCKED_BY_XSS_AUDITOR

This morning I was trying to write a quick blog post here, but when I submitted it, I got this error from Google Chrome:

chrome-xss.png

This page isn’t working

Chrome detected unusual code on this page and blocked it to protect your personal information (for example, passwords, phone numbers, and credit cards).
Try visiting the site's homepage.
ERR_BLOCKED_BY_XSS_AUDITOR

I know for sure that there was no personal information in the submitted content, because it was a list of MathJax tutorials along with a few code examples.

Not only did Chrome block me from posting the blog post, it deleted the history of my blog post from the browser so that I couldn't recover my text by using the back button.

Is anyone else encountering this problem? In the meantime, I will have to use Firefox to submit the blog post.

Update: it happened again with a different site when I tried to post embedded YouTube videos (which use iframe elements).

Update, April 30, 2017: I think this bug happens when previewing content that contains iframe or script tags. When both the source code and rendered tags are sent to the browser, Google Chrome blocks the submission. It should now be possible to reproduce the bug by posting a comment here on this site (using Google Chrome) and previewing the content before submitting it.

Sat, 2017-04-08 00:13
Offline
Joined: 7 months 2 weeks ago

XSS_AUDITOR bug


This bug forces me to switch to FireFox

Sun, 2017-04-30 12:23
Offline
Joined: 2 years 1 month ago

Testing <iframe> in chrome


<iframe>This is an iframe</iframe>

Sun, 2017-04-30 12:25
Offline
Joined: 2 years 1 month ago

Testing <script> in chrome


<script>alert('This is a script tag with javascript');</script>

Sun, 2017-04-30 12:36
Offline
Joined: 2 years 1 month ago

Testing Josh's blocked <iframe> in Chrome


<iframe width="560" height="315" src="https://www.youtube-nocookie.com/embed/WEghIXs8F6c?rel=0" frameborder="0" allowfullscreen></iframe>

Sun, 2017-04-30 12:37
Offline
Joined: 2 years 1 month ago

Testing Josh's blocked <iframe> in Chrome, without <code> tags.


This below is probably empty, or is it?

Sun, 2017-04-30 12:42
Offline
Joined: 2 years 8 months ago

Thanks for checking. That


Thanks for checking. That YouTube code causes Google Chrome to block me from posting. Over 1,500 people have read this post, so I'm guessing that it is happening to a significant number of people. (Those are just the ones who knew how to search Google for an error message and who then scrolled down the page to click on this result.) I don't know why it is happening to some people but not others.

Sun, 2017-04-30 12:50
Offline
Joined: 2 years 1 month ago

The comment above contains


The comment above contains some javascript and triggers an annoying but harmless alert when this page is loaded.

Below should be an iframe, unless Chrome blocks it.