Closed Bug 1826448 Opened 3 years ago Closed 3 years ago

windows mail application hide fullscreen notification lead to spoof

Categories

(Core :: DOM: Core & HTML, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1816287

People

(Reporter: sas.kunz, Unassigned)

Details

(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])

Attachments

(2 files)

Attached file pocfirefox.html

I found a vulnerability on firefox 110.0.1 (64-bit) (i tested on windows OS) where windows mail application can cover fullscreen notifications which can lead to spoofs.

step to reproduces:

  1. open http://103.186.0.20/firefoxmail.html or pocfirefox.html
  2. press "Open Fullscreen" button
Flags: sec-bounty?

It's not really clear what the browser is expected to do against this. I guess we could resurface the warning on window focus? No other browser seems to do something to help against this either, as far as I can tell.

Group: firefox-core-security → dom-core-security
Component: Security → DOM: Core & HTML
Product: Firefox → Core

I think this is a dupe of bug 1816287.

Status: NEW → RESOLVED
Closed: 3 years ago
Duplicate of bug: CVE-2023-37207
Resolution: --- → DUPLICATE
Flags: sec-bounty? → sec-bounty-
Group: dom-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: