Firefox installs third party plugins without prompt.




3 years ago
2 years ago


(Reporter: moltres.facesits.justin.coolidge, Unassigned, NeedInfo)


41 Branch
Windows 7

Firefox Tracking Flags

(Not tracked)




3 years ago
User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
Build ID: 20151014143721

Steps to reproduce:

Open Firefox and noticed that malware installed a toolbar in Firefox.

Actual results:

Firefox did not ask me if I wanted this addon when I opened the browser. the toolbar was installed and no question was displayed upon launch asking if I wanted to install this toolbar. Skype Click-to-call that causes Firefox freezing was also installed without prompt

Expected results:

as any other recent Firefox versions, upon Firefox launch, it should ask if I want these third party plugins installed and provide the same way of saying "no". remove the checkbox


3 years ago
Component: Untriaged → Security
OS: Unspecified → Windows 7
Hardware: Unspecified → x86_64

Comment 1

3 years ago
Can you provide the add-ons in question? There should be XPI files or folders in your profile corresponding to them, and we'll need their IDs if we want to blocklist them (and their contents to work out if/how they bypassed the normal install processes).
Flags: needinfo?(moltres.facesits.justin.coolidge)
Group: firefox-core-security

Comment 2

3 years ago
I have no clue on how to do that. I removed it using a Malware sweeper and Skype Click-to-call was also uninstalled with uninstaller. 

May I add that there is no option to remove these third party addons in tools--addons which brings us back to the days of Firefox 3.x. all recent Firefox builds allowed removing of all addons from tools/addons, not Firefox 41
Flags: needinfo?(moltres.facesits.justin.coolidge)

Comment 3

3 years ago
(In reply to Moltres Rider from comment #2)
> I have no clue on how to do that.

Flags: needinfo?(moltres.facesits.justin.coolidge)

Comment 4

2 years ago
No info provided by reporter in two years, hence closing as incomplete.
Last Resolved: 2 years ago
Resolution: --- → INCOMPLETE
You need to log in before you can comment on or make changes to this bug.