angler-fishThe Vulnerability History Project

Fix extension bindings injection for iframes

      For iframes, we don't want to use the source url for determining the
associated extension because it starts out with an about:blank context
that is scriptable by its parent.

BUG=573131

Review-Url: https://codereview.chromium.org/2151693002
Cr-Commit-Position: refs/heads/master@{#407214}
    
commit 91f655b19888da3f86b57ad8c548da93e7b9aba4
-61
-32
-11
-64
-7
-13
-5
+1 -1
+2 -15
expand_less