external protocol handlers opened without asking first
Categories
(Firefox for iOS :: General, defect)
Tracking
()
People
(Reporter: yigitcnyilmaz, Assigned: garvan)
References
()
Details
(Keywords: reporter-external, sec-low)
Attachments
(1 file)
41.77 KB,
image/png
|
Details |
Comment 1•7 years ago
|
||
Comment hidden (off-topic) |
Comment hidden (off-topic) |
Updated•7 years ago
|
Comment hidden (off-topic) |
Comment hidden (off-topic) |
Comment 7•7 years ago
|
||
Comment 9•7 years ago
|
||
Comment 10•7 years ago
|
||
Comment 11•7 years ago
|
||
Comment 13•6 years ago
|
||
Comment hidden (off-topic) |
Comment hidden (me-too) |
Comment hidden (off-topic) |
Updated•6 years ago
|
Comment hidden (off-topic) |
Comment hidden (off-topic) |
Updated•6 years ago
|
Reporter | ||
Comment 19•6 years ago
|
||
Hello,
Mozilla firefox team has solved this problem ? It has been 7 months. I am concerned whether the iOS team is working on this issue.
Please solve this issue.
Updated•6 years ago
|
Assignee | ||
Comment 20•6 years ago
|
||
Steps to reproduce:
1- Download Firefox for iOS in App Store
2- Open the this website with firefox iOS : http://yigitcanyilmaz.hol.es/scheme
3- Wait
The repro page is no longer up.
Reporter | ||
Comment 21•6 years ago
|
||
Hello,
New proof of concept is here : https://yigittestman.000webhostapp.com/redirect . Please check it.
Thanks,
Yiğit Can YILMAZ
Assignee | ||
Comment 22•6 years ago
|
||
Confirmed bug is still happening. I'll fix this.
Daniel: We should do a bug bounty for this one.
Assignee | ||
Comment 23•6 years ago
|
||
Assignee | ||
Comment 24•6 years ago
|
||
Will go out in Firefox 18.
Is a low-risk issue as there would be additional steps a user would have to take after the URL opened a draft mail or draft SMS.
Comment hidden (off-topic) |
Comment hidden (off-topic) |
Comment hidden (off-topic) |
Comment hidden (off-topic) |
Comment 30•6 years ago
|
||
Making this a sec-low issue on examination. This does not qualify for a bounty as a sec-low issue because the protocols in question are not dangerous and require a prompt before sending.
If you have questions, please email security@mozilla.org instead of leaving repeated off-topic comments here in the bug.
Updated•6 years ago
|
Updated•5 years ago
|
Updated•1 year ago
|
Description
•