I'm working on a bachelor's in network security and I'm not exactly sure how you feel this is a security problem. If anything, it's keeping calls more internalized, thus showing some reduction in risk.
This is outside of network security, it's website security 101.
Dead simple, really: If "somehow" a party with malicious intend were to sneak a link to a phishing website in and the user were to click it, the entire session would be hijacked and looking extremely legit, especially if the client's URL and navigation bar were disabled.
Once you have the session, you wouldn't even go for the log-in data but simply present yourself as Steam and intercept CC details on a purchase as there are bound to be people that do not store their CC data with Steam and instead enter them each time they make a purchase.
If such a thing were to happen Valve would probably be very much liable in a legal sense. I'm not a lawyer of course.
Check any 3rd party site link in the Steam community. In your regular browser you get prompted with this:
"Note: the URL you have clicked on is not an official Steam web site.
URL-you-just-clicked
If this web site asks for your user name or password, do not enter that information. You could lose your Steam account and all your games!
Are you sure you want to visit this page? Click OK to continue at your own risk."
If you open it from within client it opens your default browser for exactly these anti-phishing reasons.
1: That doesn't make Valve liable.
2: While it's presently trivial to strip SSL out of transactions SHOULD you manage to get a phishing URL, it's no more risky than entering your information each time due to the rising chance of a java-based, cross-platform session jack on the actual web client which doesn't necessarily stop it.
The issue here is that, really, it should present the same warning in client. Potentially, a feature request for a toggle to select where links open.
The only difference between the client's activity and a default-browser's is that the latter shows the warning; it probably doesn't prevent the attack should you ignore it.
Sidebar: Web security is part of the infosec sphere... which is what the Network Security degree is.
Web pages opening in the client is not considered a high risk, but it also usually only happens from an authoring error on the Steam page or a bug. For example, when I go look at Towns the links there take me to Steam pages. How did you get to the third-party Towns page?
I've also seen people with Facebook coming up in the client and that doesn't happen for me; it's opened in my external browser. If you aren't seeing that it's possible this was a bug and was already fixed.
As for adding a warning about external content the web team tries to set those up and they'll continue to work on that, but it isn't a Linux issue.
As far as I can tell this issue also happens on Windows and only when clicking third party links that are part of a News item (Stuff you see when clicking on the big News button that is part of the Steam UI). I simply got to the Towns site by clicking a link in their 24 Jan 2013 update news post from within the client.
This really doesn't look like expected behavior because on any 3rd party site (except Facebook) I have tried the home button becomes unresponsive and simply does nothing.
OK, I can repro, I was looking at the update from the 27th, which didn't have a link. The link in the update on the 24th probably should have gotten filtered out.
The home button tries to go to the home of where you're at (store, community, etc.) so it only really makes sense for Steam pages. There is no global "home" concept that it will always return to.
Closing as the referenced url to a third party site now opens in the default browser instead of in the client.
Nothing extracted yet.
I went to read the latest update for Towns which included a link to their website. After clicking the link the site was loaded within the Steam client, as shown in the image, instead of opening the standard browser, which is the expected behavior.
I tested several other news items that included links to third party sites and they all open in the actual client.
I think I don't need to tell anyone that this is a bit of a security problem.