Open Bug 1501072 Opened 7 years ago Updated 8 days ago

PContentPermissionRequest can be forged by a Rogue Content Process

Categories

(Core :: DOM: Security, enhancement, P3)

enhancement

Tracking

()

Fission Milestone Future

People

(Reporter: tjr, Unassigned)

References

(Depends on 1 open bug, Blocks 2 open bugs)

Details

(Keywords: sec-want, Whiteboard: [domsecurity-backlog2])

PContent::PContentPermissionRequest accepts a principal from the content process and uses it to request and store permissions. A rogue content process could supply a fraudulent principal and potentially trick the user into granting access for a different domain. Alternately, I believe the Content Process could supply a principal the user has granted persistent access to and thus bypass the permission check. We should validate the principal supplies is valid for the origins the content process is hosting.
Priority: -- → P3
Whiteboard: [domsecurity-backlog2]

This bug is not a Fission MVP blocker.

Fission Milestone: --- → Future
Severity: normal → S3
See Also: → 2023115
Duplicate of this bug: 2023115
See Also: 2023115 →
Duplicate of this bug: 2025190
Duplicate of this bug: 2025871
Duplicate of this bug: 2034465
Duplicate of this bug: 2036639
Duplicate of this bug: 2044638
Duplicate of this bug: 2050450
Duplicate of this bug: 2051472
Keywords: sec-want
Duplicate of this bug: 2051924
Duplicate of this bug: 2052524
Duplicate of this bug: 2054694
Assignee: nobody → tschuster
Duplicate of this bug: 2054944

I did some investigation into this, and it looks like there is actually a big blocker for doing this work.

The webcompat addon uses the privileged requestStorageAccessForOrigin API to actually do third-party permission request to unblock broken pages. We can't tell whether that request is actually coming from the web compat code or a malicious content process.

The relevant test failures are in toolkit/components/antitracking/test/browser/browser_storageAccessPrivilegeAPI.js.

I am unassigning myself for now to focus on something else, I had hoped this would be a simple change.

Assignee: tschuster → nobody
Duplicate of this bug: 2058374
Duplicate of this bug: 2064465
Duplicate of this bug: 2065453
Duplicate of this bug: 2067054
Duplicate of this bug: 2067424
Duplicate of this bug: 2070042
Duplicate of this bug: 2070685
Duplicate of this bug: 2073958
Duplicate of this bug: 2075898
Duplicate of this bug: 2076076
Duplicate of this bug: 2076301
You need to log in before you can comment on or make changes to this bug.