Update. Looking at the current implementation, we've already specified that we will not intercept fallback URL. https://searchfox.org/mozilla-mobile/rev/2655756f8d424489c4dda3486c7cec3bd408f347/firefox-android/android-components/components/concept/engine/src/main/java/mozilla/components/concept/engine/request/RequestInterceptor.kt#38 The attacker should not be able to user fallback URL to trigger applinks and redirect to another application.
Bug 1810705 Comment 67 Edit History
Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.
Update. Looking at the current implementation, we've already specified that we will not intercept fallback URL. https://searchfox.org/mozilla-mobile/rev/2655756f8d424489c4dda3486c7cec3bd408f347/firefox-android/android-components/components/concept/engine/src/main/java/mozilla/components/concept/engine/request/RequestInterceptor.kt#38 The attacker should not be able to use fallback URL to trigger applinks and redirect to another application.
Update. Looking at the current implementation, we've already specified that we will not intercept fallback URL. https://searchfox.org/mozilla-mobile/rev/2655756f8d424489c4dda3486c7cec3bd408f347/firefox-android/android-components/components/concept/engine/src/main/java/mozilla/components/concept/engine/request/RequestInterceptor.kt#38 This was introduce last February last year to fix an unrelated issue. https://bugzilla.mozilla.org/show_bug.cgi?id=1809269 The attacker should not be able to use fallback URL to trigger applinks and redirect to another application.
Update. Looking at the current implementation, we've already specified that we will not intercept fallback URL. https://searchfox.org/mozilla-mobile/rev/2655756f8d424489c4dda3486c7cec3bd408f347/firefox-android/android-components/components/concept/engine/src/main/java/mozilla/components/concept/engine/request/RequestInterceptor.kt#38 This was introduced last February last year to fix an unrelated issue. https://bugzilla.mozilla.org/show_bug.cgi?id=1809269. The attacker should not be able to use fallback URL to trigger applinks and redirect to another application.
Update. Looking at the current implementation, we've already specified that we will not intercept fallback URL. https://searchfox.org/mozilla-mobile/rev/2655756f8d424489c4dda3486c7cec3bd408f347/firefox-android/android-components/components/concept/engine/src/main/java/mozilla/components/concept/engine/request/RequestInterceptor.kt#38 This was introduced February last year to fix an unrelated issue. https://bugzilla.mozilla.org/show_bug.cgi?id=1809269. The attacker should not be able to use fallback URL to trigger applinks and redirect to another application.