tapjacking to allow permission
Categories
(Firefox for Android :: General, defect, P3)
Tracking
()
People
(Reporter: sas.kunz, Assigned: amejia)
References
Details
(Keywords: csectype-clickjacking, reporter-external, sec-moderate, Whiteboard: [reporter-external] [client-bounty-form] [verif?])
Attachments
(4 files)
i found tapjacking vulnerability on firefox to allow permission
steps to produce:
- Open https://pipabajabakrie.com/upload/firefox.html or firefox_tapjacking.html
(if you cannot access https://pipabajabakrie.com/upload/firefox.html you can run your own webserver(it must using domain name) (copy
filefox_tapjacking.html) - tap on "click here button"
- double tap on "Ok" button
Updated•2 years ago
|
Comment 3•2 years ago
|
||
The severity field is not set for this bug.
:jonalmeida, could you have a look please?
For more information, please visit BugBot documentation.
Updated•2 years ago
|
Updated•2 years ago
|
Updated•1 year ago
|
Updated•1 year ago
|
Updated•1 year ago
|
after fixing at 1836786 I can still reproduce this bug and it seems the fix is indeed different from 1836786
On 1836786 it was fixed with a delay in the permission dialog whereas in this bug there was no delay because it was probably blocked by the window prompt
Comment 7•1 year ago
|
||
I can't reproduce anything like either of your two movies (before and after the fix in bug 1836786) -- for me the permission prompt is shown before and on top of the prompt. In the code it looks like the timeouts are about 100ms, and that's way shorter than the time it takes for me to get my fingers from the button at the top of the screen to the buttons at the bottom.
Hi Daniel I can still reproduce it in the latest version of Nightly. If the permission prompt is above the window prompt you can refresh the page and start again
Comment 10•1 year ago
|
||
It mostly didn't work for me because the permission prompt shows up on top, but I did eventually reproduce it twice out of 15-20 attempts.
"double-click on the OK button" is a weird thing to ask people to do so I'm dubious this is an effective spoof, but clearly our delay doesn't take into account the fact that the prompt doesn't have focus and is obscured by another prompt.
Comment 11•1 year ago
|
||
In the current Nightly 130.0a1 this is not spoofing anymore because the prompt is not shown.
Comment 12•1 year ago
|
||
fixed, possibly by bug 1908344
| Assignee | ||
Comment 14•1 year ago
|
||
Confirmed, it's the same issue we addressed on bug 1908344
Updated•1 year ago
|
Updated•9 months ago
|
Description
•