Closed Bug 1837581 Opened 2 years ago Closed 2 years ago

<datalist> options box using absolute position when exiting fullscreen which causes it to overlay address bar

Categories

(Toolkit :: Autocomplete, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1828259

People

(Reporter: haxatron1, Unassigned)

References

()

Details

(Keywords: csectype-spoof, reporter-external, sec-moderate, Whiteboard: [reporter-external] [client-bounty-form] [verif?])

Attachments

(2 files)

The <datalist> options box uses absolute position. Therefore, when placed where the address bar is normally located and exit fullscreen, it can cause it to overlay address bar.

(1): Go to https://sly-heavenly-wasabi.glitch.me/select.html
(2): Click anywhere on page to enter fullscreen
(3): Go to input box and key in "h". Fullscreen exit and options box overlay address bar.

The options box should close when exiting fullscreen.

Tested on 114.

Flags: sec-bounty?
Attached file select.html
Duplicate of this bug: 1837580
Group: firefox-core-security → dom-core-security
Component: Security → DOM: Core & HTML
Product: Firefox → Core

Maybe this is more like Layout because of the box positioning than about full screen per se.

Group: dom-core-security → layout-core-security
Component: DOM: Core & HTML → Layout: Form Controls
Keywords: csectype-spoof
See Also: → CVE-2023-32212

Possibly a dupe of bug 1828259.

I do think this has something to do with fullscreen. Basically what happens is when the screen size of the page gets bigger when exiting fullscreen the position of the box remains the same -- so when the box is where the address bar is normally located and the fullscreen is exit, the box will cover the address bar once fullscreen has exited.

Emilio, is this a dupe of bug 1828259? Thanks.

Flags: needinfo?(emilio)

Yes, effectively.

Status: NEW → RESOLVED
Closed: 2 years ago
Duplicate of bug: CVE-2024-5698
Flags: needinfo?(emilio)
Resolution: --- → DUPLICATE
Group: layout-core-security → firefox-core-security
Component: Layout: Form Controls → Autocomplete
Product: Core → Toolkit
Flags: sec-bounty? → sec-bounty-
Group: firefox-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: