Open Bug 1717671 Opened 5 years ago Updated 6 months ago

Avoid the use of a persistent UUID in the public base URL of extensions

Categories

(WebExtensions :: General, enhancement, P3)

enhancement
Points:
5

Tracking

(Not tracked)

People

(Reporter: robwu, Unassigned)

References

(Blocks 4 open bugs)

Details

(Keywords: sec-want, Whiteboard: [mv3-future][fingerprinting])

Extension resources are currently served at a URL with a UUID as hostname (generated at install time) - moz-extension://UUID. This UUID is persistent and if leaked can cause privacy issues (e.g. bug 1405971, bug 1372288) or security issues (e.g. bug 1711361).

There are generally two ways to resolve this:

  • Remove the need for leaking UUIDs. Extensions leak UUIDs when they share a file in web_accessible_resources with a website. With alternatives (e.g. bug 1712096 and bug 1340930), extensions don't need to declare an item in web_accessible_resources any more.
  • Reduce the scope/lifetime of UUID.

This bug is about the latter: we should try to decouple the UUID from the extension URLs. This is far from trivial, because the UUID appears in the moz-extension:-base URL, which is also part of the principal used for permissions/storage/etc and persisted to disk. Extensions currently break when the UUID is reset (bug 1696779).

Solving this issue in general is difficult, but we can experiment with non-persistent UUID for one or more built-in extensions (e.g. webcompat).

Other browsers:

See Also: → CVE-2025-6425

Could Bug 1322304 be associated with this bug?

Severity: -- → N/A
Priority: -- → P3
Whiteboard: [mv3-future]
Points: --- → 5

An interesting consideration here would be CORS. Currently, servers can allow requests from only their own extensions by checking the origin header. If this change has implications for that header value, this could be a regression in that sense.

Whiteboard: [mv3-future] → [mv3-future][sp3]
Keywords: sec-want
Whiteboard: [mv3-future][sp3] → [mv3-future][sp3][fingerprinting]

There is another edge case where a persistent UUID might be leaked.

Some extensions (e.g. userscript managers) use sourceURL to display the scripts in the Developer Tools Debugger. In order to display them under extension's own entry, UUID is used. (e.g. bug 1824910)

If the extension injects the script into the webpage context, the sourceURL could become visible to the webpage.

Whiteboard: [mv3-future][sp3][fingerprinting] → [mv3-future][fingerprinting]
You need to log in before you can comment on or make changes to this bug.