Closed Bug 1618814 Opened 1 year ago Closed 1 year ago

Extension block request: Add-ons executing remote code

Categories

(Toolkit :: Blocklist Policy Requests, task)

task
Not set
normal

Tracking

()

RESOLVED FIXED

People

(Reporter: TheOne, Assigned: TheOne)

Details

(Whiteboard: [extension])

Extension name Add-ons executing remote code
Extension versions affected <all versions>
Platforms affected <all platforms>
Block severity hard

Reason

I’ve reviewed the add-ons and confirmed they are executing remote code.

Extension GUIDs

{0aa583da-e323-42f2-b4d2-0bc61b493171}
{20a15a74-371f-5098-a362-bd127db4f8bc}
{c11016db-e96e-4eb7-bc19-7121d96d0e2f}
{0fadbf07-bb25-4737-9800-b879a6e1c417}
{e7fefcf3-b39c-4f17-5215-ebfe120a7031}
{f85238e5-862b-45aa-9d66-0ab56a032375}
{ea3f3dc3-6fbc-450d-9120-07b3b03cd9ec}
{aa909324-7520-4dcd-9eb0-9f0a9ec3c003}
{807833d9-8ea7-42f8-a8a4-46ff7519dd8b}
{92047279-0910-4abb-beb7-a7f2cd6cf04b}
{94036cd5-1829-4480-ab0b-e2455deafb9c}
{05d0e324-7d90-3e2d-2eb0-6f1a9ec3c003}
{abd0e324-7120-3dcd-3eb0-9f1a9ec3c003}
{578e48b0-7c9b-4890-91ff-f6ce3e958edb}
{0aa583da-e323-42f2-b4d2-0bc61b493183}
{72d08da8-8277-47f0-8bee-ba5ad40dda6c}
{9fd0e085-1545-13de-a831-ab9a05dcf253}
{ced9def2-2d86-4a1b-a9eb-29e2f3c9eb48}
{364f2138-c271-47a3-9ddc-466c4a27feef}

The block has been staged. Simon, can you review and push?

Flags: needinfo?(sbennetts)

Done.

Group: blocklist-requests
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Flags: needinfo?(sbennetts)
Resolution: --- → FIXED

Hi,

It looks like this update has removed an extension I have enjoyed the use of for a long time, "Dark Mode".
The add-ons page offers very little explanation, nor does the link following it: https://i.imgur.com/PpXCbtV.png
Could you please offer some enlightenment as to why this add-on has been removed?

Thanks,

  • Jack
Flags: needinfo?(awagner)

What's happening with this "Dark Mode Dark Reader" extension? Is it secure or is it stealing user's data?
It would be a shame to see it go, it is an extremely useful really great extension to Firefox. So good in fact that it should be built in..

Flags: needinfo?(scolville)
Flags: needinfo?(scolville)
Flags: needinfo?(awagner)

Thank you.
It has exactly the same user interface as "Dark Mode" which got reported in this bug. Is it the same extension then?
More importantly was "Dark Mode" a copy that way stealing our data? Should we change all passwords now??!

I was also using the Dark Mode extension, which seems to to be a sightly outdated clone of Dark Reader now that I've installed the real extension... So it seems pretty apparent it was just a clone of the official extension bundled with malicious intent. I'm actually pretty surprised I fell for that, but it seemed legitimate at the time. What was the nature of the remote code execution? I've been running the extension for a while now and wonder what kinds of security breaches may have occurred? Are there any samples of the code that the extension was pulling end executing?

gvandereay's question is very important. Please let us know what exactly "Dark Mode" was doing and if our data security could be compromised.

We appreciate your comments but this is not a discussion forum. The block reason is stated in the initial comment. Please see the Reason section. The nature of remote code is that it can be different for any user and can change at any time. Therefore, execution of remote code is forbidden by our policies.

Our general discussion forums are at discourse.mozilla.org/c/add-ons/
Thank you for your understanding.

Restrict Comments: true
You need to log in before you can comment on or make changes to this bug.