Web Share can be used to attach file:/// URLs
Categories
(Firefox for iOS :: Third Party Security Issues, defect)
Tracking
()
| Tracking | Status | |
|---|---|---|
| fxios | - | --- |
People
(Reporter: agashlin, Unassigned)
References
()
Details
(Keywords: sec-audit, sec-vector)
The PoC released today (see URL) for Safari uses Web Share with a file: URL to share local files in an obscured way, this fairly easily can lead to attaching them to an email with the iOS Mail app. This also affects Firefox for iOS.
(apologies if it doesn't make sense to submit this given it may not be in our power to fix, but it seemed prudent to report)
Comment 1•5 years ago
|
||
Hi Adam, can you clarify how this affects Firefox for iOS... is that because WKWebView natively provides access to the API?
Comment 2•5 years ago
|
||
Marcos, Yes.
And the bug was open to understand if Firefox iOS could mitigate on top on WKWebView.
Comment 3•5 years ago
|
||
Does it make sense to keep this hidden if the PoC is public and it's known all iOS browsers are really webkit inside?
| Reporter | ||
Comment 4•5 years ago
|
||
I don't think it needs to be hidden, but I wanted to leave that decision to the pros.
Comment 5•5 years ago
|
||
The severity field is not set for this bug.
:garvan, could you have a look please?
For more information, please visit auto_nag documentation.
Closing since can't reproduce, fixed by Webkit.
Updated•3 years ago
|
Updated•3 years ago
|
Updated•1 year ago
|
Description
•