Closed Bug 1489950 Opened 6 years ago Closed 3 years ago

Firefox Focus for Android v6.1.1 allow attackers to modify apps without affecting their signature

Categories

(Focus :: General, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: Bean3ai, Unassigned)

References

Details

(Keywords: csectype-priv-escalation, sec-moderate)

Attachments

(2 files)

Attached image fiefox Focus.jpg
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36 Steps to reproduce: Checking the Firefox for Android App`s signature information, I notice that Firefox Focus for Android v6.1.1 is using signature scheme version 1. App`s signature information screenshots attached. Actual results: It is a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This vulnerability (designated as CVE-2017-13156, and also called the Janus vulnerability) affects versions of Android from 5.1.1 to 8.0 Expected results: For compatibility reasons, developer could use a mixed signature (version 1 and 2) scheme.
Attached image focus v1.jpg
Component: Build Config & IDE Support → Security: Android
Flags: needinfo?(sdaswani)
Product: Firefox for Android → Focus
Version: unspecified → ---
will also wait for a rating from the security team before prioritizing this work.
Flags: needinfo?(sdaswani)
ulfr: does your team/Autograph do the signing for android apps?
We do (at least for some). V2/V3 signature support is in the backlog. AAB adoption may impact this.
Group: firefox-core-security → mobile-core-security
Whiteboard: [geckoview]

This is release engineering work that is independent of GV. Possibly this bug should be moved to them?

Whiteboard: [geckoview]

Catlee can you help find someone in releng who might work on this?

Flags: needinfo?(catlee)

as per comment #5, signing of Android apps is handled by Autograph. I think the work rests with :ulfr's team, unless we decide to bring signing back into something like a releng scriptworker.

Flags: needinfo?(catlee)

APK v2 and v3 sig support is a Q3 OKR for :ulfr

Fixed for all APKs in bug 1613113 and bug 1669487

Status: UNCONFIRMED → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Group: mobile-core-security → core-security-release
Group: core-security-release
Component: Security: Android → General
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: