Closed Bug 1692654 Opened 4 years ago Closed 4 years ago

SameSite cookie Reader View bypass

Categories

(Firefox :: Security, task)

task

Tracking

()

RESOLVED DUPLICATE of bug 1692655

People

(Reporter: whoismath, Unassigned)

References

()

Details

(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])

Attachments

(1 file)

Attached file files.zip

User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:85.0) Gecko/20100101 Firefox/85.0

Steps to reproduce:

  1. Go to https://abrasax.club/readcookie.html
  2. Click anywhere in the page to open another tab.
  3. Click in Reader View icon.
  4. Wait 15 seconds until the new tab is redirected to about:blank
  5. Wait 4 seconds more to be redirected back to Reader View.
  6. Reader View will render meta redirect page and SameSite cookie will be bypassed.

Actual results:

SameSite cookie is sent when Reader View is reloaded with a meta redirect.

Expected results:

SameSite cookie not sent.

Flags: sec-bounty?

I assume this is the same as 1692655?

Status: UNCONFIRMED → RESOLVED
Closed: 4 years ago
Resolution: --- → DUPLICATE
Flags: sec-bounty?
Group: firefox-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: