I investigated the Permission Prompt Origin Spoofing vector defined by the reporter. I came to the conclusion that [the logic we currently have in the child actor](https://searchfox.org/firefox-main/rev/8d0f55f3e63334ef6a855d12d756954c7ddb97aa/mobile/shared/actors/GeckoViewPermissionChild.sys.mjs#94-180) for permission prompts doesn't actually need to be in the content process at all. I am actually not sure if there is even a need for a URI spoofing - I think simply because we have that function defined in the content process, if somebody achieves ACE/RCE, they can simply return "allow" from that function. So the problem here is not so much absence of the URI validation, but rather the presence of that function in the content process at all. I experimented with moving that logic (and some of the parent actor logic as well) into the `GeckoViewPermission` module, and was able to get the tests passing. Before making a patch, I would like to add a couple of tests cases with two GeckoSessions and with multiple subframes, just to make sure everything functions correctly. I will also investigate our other APIs (that are not mentioned in this bug), to make sure we don't have too much critical logic in the content process, and to see if there are any validation checks I can add.
Bug 2003171 Comment 8 Edit History
Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.
I investigated the Permission Prompt Origin Spoofing vector defined by the reporter. I came to the conclusion that [the logic we currently have in the child actor](https://searchfox.org/firefox-main/rev/8d0f55f3e63334ef6a855d12d756954c7ddb97aa/mobile/shared/actors/GeckoViewPermissionChild.sys.mjs#94-180) for permission prompts doesn't actually need to be in the content process at all. I am actually not sure if there is even a need for a URI spoofing - I think simply because we have that function defined in the content process, if somebody achieves ACE/RCE, they can simply return "allow" from that function. So the problem here is not so much absence of the URI validation, but rather the presence of that function in the content process at all. I experimented with moving that logic (and some of the parent actor logic as well) into the `GeckoViewPermission` module, and was able to get the tests passing. Before making a patch, I would like to add a couple of tests cases with two GeckoSessions and with multiple subframes, just to make sure everything still functions correctly with my fix. I will also investigate our other APIs (that are not mentioned in this bug), to make sure we don't have too much critical logic in the content process, and to see if there are any validation checks I can add.