| I worked on this. The quote is true, in all honesty. Same as downloading and running applications from the web. We do our best to make sure the scenario listed doesn't happen. For instance, on Windows, after a writer is closed, we apply the Mark-of-the-Web, apply SafeBrowsing checks and finally call a system API which may trigger an anti-virus check. On the Mac, we apply the equivalent of Mark-of-the-Web. You may have noticed that when you open the file, sometimes it asks you to ensure the provenance of the file? Basically, it's a similar procedure as for file downloads. Edit: I forgot to say that "sensitive" directories are not allowed.
Think C:\Windows, etc. https://source.chromium.org/chromium/chromium/src/+/master:c... |