screen recording disabled in incognito mode, still leaking sensitive information in the address bar.
Categories
(Fenix :: Toolbar, defect, P3)
Tracking
(firefox110 wontfix, firefox111 wontfix, firefox112 verified)
People
(Reporter: hackerone3117, Assigned: aputanu)
References
Details
(Keywords: privacy, reporter-external, sec-low, Whiteboard: [adv-main112+][reporter-external] [web-bounty-form])
Attachments
(4 files, 1 obsolete file)
hi Firefox.
I noticed that Firefox for android has a feature to disable screen capture/screenshot on incognito tabs, but the feature still leaks information in the address bar while recording the screen.
production step:
- Install Firefox for Android with the latest version
- then disable the screen recording feature/screenshot for incognito tabs
- And testing, screen recording, see the address bar is still visible, allowing the victim's sensitive parameters to be exposed in the wild.
impact :
The attacker can see sensitive information in the victim's address bar, in the form of access tokens, emails, passwords, even secret parameters, etc..
Comment hidden (duplicate) |
Comment 3•3 years ago
|
||
I'm not sure this feature was meant to hide your keyboard -- that's not part of the page. The autocomplete stuff likewise could be from your bookmarks or history saved in non-incognito mode and might not be considered part of this protection.
Kevin: do you know what the design/intent for this restriction was?
thanks for your reply.
I believe this is a problem because I don't see other browsers like chrome, edge, Opera etc, leaking the address bar while recording screen in incognito mode.
I'm not sure this feature was meant to hide your keyboard.
I didn't type the keyboard but the address bar which was still exposed in the wild when the recording happened.
Comment hidden (duplicate) |
Comment hidden (duplicate) |
Comment hidden (offtopic) |
Updated•2 years ago
|
Updated•2 years ago
|
Comment hidden (duplicate) |
Comment 10•2 years ago
•
|
||
We're waiting for an answer from the Product folks about the intent of this design. The tiny amount of the URL that shows would reveal the site, but not any content details. Wouldn't it be easier to blank the whole screen than to exempt the toolbar part? That's what makes me wonder if this approach is intentional.
Comment 11•2 years ago
|
||
Folks have been on vacation. Kevin says they were going to cover this bug in their team meeting tomorrow
Reporter | ||
Comment 12•2 years ago
|
||
thanks for your reply.
I'm also not sure this is really a Low
category as it violates your browser policy which says not to show sensitive data in incognito mode.
It's only vulnerable on Firefox, in other browsers chrome, edge, Opera etc, showing black screen including address bar.
Regards
Comment 13•2 years ago
|
||
I can confirm the behavior in nightly and going back to v84 has essentially the same behavior. I believe we should mark all the elements that are part of private browsing as FLAG_SECURE. However I agree with Dan's assessment of the severity.
Updated•2 years ago
|
Updated•2 years ago
|
Comment 14•2 years ago
|
||
Bug for the Android Experience team
Updated•2 years ago
|
Comment hidden (duplicate) |
Updated•2 years ago
|
Assignee | ||
Comment 16•2 years ago
|
||
Assignee | ||
Updated•2 years ago
|
Comment hidden (duplicate) |
Comment 18•2 years ago
|
||
Hi Irwan,
thank you for reporting this bug!
Unfortunately, we have made the decision to not award a bounty for your submission. We generally do not pay for bugs with a severity of "low". Furthermore, we consider this a privacy issue more than a security issue. The address bar content is indeed unintentionally leaked, but that requires someone to be actually able to record the screen without approval. We also note that most secret URL parameters are at the end of the address and likely not easily seen.
We're looking forward to your next submission and want to point out that there are various tips for finding and testing higher severity issues in our guidelines at https://www.mozilla.org/en-US/security/client-bug-bounty/.
Updated•2 years ago
|
Comment 19•2 years ago
•
|
||
Verified as fixed on Nightly 112.0a1 from 02/21 with Google Pixel 7 PRO (Android 13) and Motorola Moto G9 plus (Android 11). The address bar is not displayed during screen recording in private mode.
Updated•2 years ago
|
Updated•2 years ago
|
Comment 20•2 years ago
|
||
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Comment 21•2 years ago
|
||
Updated•2 years ago
|
Updated•1 year ago
|
Updated•8 months ago
|
Updated•8 months ago
|
Description
•