[a11y] Restrict AXModes more aggressively with IA2

We noticed that accessibility for web content gets enabled
for all users Chrome/Chromium users on Windows 11. The
common root cause we found so far is coming from the "windows
manager" view that shows up when you hover the full screen button on
Windows 11 (the one right next to the minimize or close buttons).
This view appears to be using UI Automation, and since UIA isn't
enabled in Chrome and Chromium (yet), it reverts back to using the
UIA to IA2 bridge.

The strangest part was that Microsoft Edge wasn't impacted by this.
While investigating, we found that the functions that get called
by UIA in Chromium (when UIA is enabled) and Edge (where UIA is
enabled) actually only turn on accessibility in the web content when
we are querying UIA information from a web content.

The functions that get called by IA2 do it differently: they enable
accessibility for the web content in all cases, regardless of whether
we are on a browser view node or a web content node.

In this CL, we restrict the IA2 AXMode enablement to also check
whether the node we're querying accessible information from is in
fact a web content node.

As Jacques mentioned in the comments below, one potential concern we
have with this change is that non-screenreader tools may be confused
as to why web contents are not immediately accessible, since even
after triggering web contents accessibility there is still a delay
while we serialize. A particularly brittle tool may fail during this
period, where they didn't before.

Since this fixes a bug that has a high impact on hundreds of millions
of users, we added a flag to effectively disable all the changes
introduced by this commit. If any issues come up because of this
commit, it's possible to disable it by launching Chromium with the
following flag:

--disable-features=AccessibilityRestrictiveIA2AXModes

Fixed: 1441213
Change-Id: I555fd28e4b15b82d6a7ee428cbd3f78452fd5144
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/4493363
Commit-Queue: Benjamin Beaudry <benjamin.beaudry@microsoft.com>
Auto-Submit: Benjamin Beaudry <benjamin.beaudry@microsoft.com>
Reviewed-by: Jacques Newman <janewman@microsoft.com>
Cr-Commit-Position: refs/heads/main@{#1137486}
5 files changed
tree: 5f4e8c719a8aa04d35c06a5317089aba0a1102ef
  1. android_webview/
  2. apps/
  3. ash/
  4. base/
  5. build/
  6. build_overrides/
  7. buildtools/
  8. cc/
  9. chrome/
  10. chromecast/
  11. chromeos/
  12. codelabs/
  13. components/
  14. content/
  15. courgette/
  16. crypto/
  17. dbus/
  18. device/
  19. docs/
  20. extensions/
  21. fuchsia_web/
  22. gin/
  23. google_apis/
  24. google_update/
  25. gpu/
  26. headless/
  27. infra/
  28. ios/
  29. ipc/
  30. media/
  31. mojo/
  32. native_client_sdk/
  33. net/
  34. pdf/
  35. ppapi/
  36. printing/
  37. remoting/
  38. rlz/
  39. sandbox/
  40. services/
  41. skia/
  42. sql/
  43. storage/
  44. styleguide/
  45. testing/
  46. third_party/
  47. tools/
  48. ui/
  49. url/
  50. weblayer/
  51. .clang-format
  52. .clang-tidy
  53. .eslintrc.js
  54. .git-blame-ignore-revs
  55. .gitattributes
  56. .gitignore
  57. .gn
  58. .mailmap
  59. .rustfmt.toml
  60. .vpython3
  61. .yapfignore
  62. ATL_OWNERS
  63. AUTHORS
  64. BUILD.gn
  65. CODE_OF_CONDUCT.md
  66. codereview.settings
  67. DEPS
  68. DIR_METADATA
  69. LICENSE
  70. LICENSE.chromium_os
  71. OWNERS
  72. PRESUBMIT.py
  73. PRESUBMIT_test.py
  74. PRESUBMIT_test_mocks.py
  75. README.md
  76. WATCHLISTS
README.md

Logo Chromium

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.

The project's web site is https://www.chromium.org.

To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.

Documentation in the source is rooted in docs/README.md.

Learn how to Get Around the Chromium Source Code Directory Structure .

For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.

If you found a bug, please file it at https://crbug.com/new.