safety browsing alert notification hides fullscreen notification on firefoxfocus, leads to spoof
Categories
(Focus :: General, defect)
Tracking
(firefox111 wontfix, firefox112 fixed, firefox113 fixed)
People
(Reporter: sas.kunz, Assigned: petru)
References
Details
(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])
Attachments
(4 files)
I found a vulnerability in firefox android where a safety browsing alert notification can cover fullscreen notifications which can lead to spoofs. i tested after fixed: https://github.com/mozilla-mobile/firefox-android/pull/1133 ( https://bugzilla.mozilla.org/show_bug.cgi?id=1819254 )
steps to produce
1, open http://103.186.0.20/focus.html or firefox.html
2. click on "go to google" button , (when the button clicked it show safety browsing alert it covers the fullscreen notification)
OS: Android 10 (Samsung M31)
i attached the poc video files.
thank you
firefox focus version:
1.0.2310(Build #11)
112.0a1-20230306094520
AS:97.1.0
Updated•2 years ago
|
Assignee | ||
Comment 3•2 years ago
|
||
Thank you!
Would be fixed with the same approach as on bug 1816059.
Assignee | ||
Comment 4•2 years ago
|
||
@Hafiizh Can you confirm that the current Nightly avoids this issue?
Assignee | ||
Comment 7•2 years ago
|
||
Thank you for the confirmation!
Assignee | ||
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Comment 8•2 years ago
|
||
As we expected, this did turn out to be fixed by the redesigned mechanism in bug 1816059 making this essentially a dupe for purposes of the bug bounty.
Comment hidden (off-topic) |
Comment 10•2 years ago
|
||
Bounty questions should be directed to security@mozilla.com, thanks.
Comment 11•2 years ago
|
||
Updated•2 years ago
|
Updated•1 year ago
|
Description
•