Closed Bug 1658144 Opened 5 years ago Closed 4 years ago

Fenix: XSS on error pages allows access to privileged APIs

Categories

(Fenix :: General, defect)

Unspecified
Android
defect

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 1657055

People

(Reporter: jupenur, Assigned: sebastian)

References

Details

(4 keywords, Whiteboard: [reporter-external] [client-bounty-form] [verif?])

Sigh (bug 873966 comment 30).

Sebastian: Looks like a dupe of bug 1657055. Can you make sure it actually is and is fixed by your patch?

Flags: needinfo?(s.kaspari)
Group: firefox-core-security → mobile-core-security
Type: task → defect
Component: Security → Security: Android
Product: Firefox → Fenix
Blocks: 1658276
Assignee: nobody → s.kaspari
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Flags: needinfo?(s.kaspari)

Looks to be fixed by 1657055. I can't reproduce in 81 or 83.

Status: ASSIGNED → RESOLVED
Closed: 4 years ago
Resolution: --- → DUPLICATE
Flags: sec-bounty? → sec-bounty-
Component: Security: Android → General
OS: Unspecified → Android
Group: mobile-core-security
You need to log in before you can comment on or make changes to this bug.