(Android) web authn permissions dialog obscured fullscreen notification lead to spoof
Categories
(Firefox for Android :: WebAuthn, defect, P2)
Tracking
()
People
(Reporter: sas.kunz, Assigned: polly)
References
Details
(Keywords: csectype-spoof, reporter-external, sec-moderate, Whiteboard: [client-bounty-form][group4][adv-main130-])
Attachments
(3 files)
After fixing it at 1823316, I found that there was another permission dialog that blocked fullscreen notifications, namely the webauthn permission.
step to reproduces:
- open https://coral-shadowed-parrot.glitch.me/spoof.html
- click website
mozilla version: nightly 121.0a1
OS version: android 12
i updated the poc
step to reproduces:
- open https://coral-shadowed-parrot.glitch.me/spoof.html
- click on "setup webauthn" button
Updated•2 years ago
|
Comment 4•2 years ago
•
|
||
Chrome also switches to fullscreen, but it shows their fullscreen warning at the bottom (very easy to miss) after the OS Auth UI goes away. The WebAuthn prompt is an OS prompt, not a Firefox one, but we do know that the promise is pending if that's useful. Or at least GeckoView does! It may not be available to the Fenix front end.
Updated•2 years ago
|
Comment 5•2 years ago
|
||
The severity field is not set for this bug.
:jonalmeida, could you have a look please?
For more information, please visit BugBot documentation.
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Comment 7•2 years ago
|
||
Titouan's fix for bug 1874795 is expected to also fix this bug. Assigning this bug to Titouan as a reminder to test this bug's STR.
Comment 9•1 years ago
|
||
Priority P1 because this bug has been assigned to a squad/group.
Updated•1 years ago
|
Updated•1 years ago
|
Reporter | ||
Comment 11•1 year ago
|
||
Hello any updates?
Comment 12•1 year ago
|
||
Polly has been working on a proposal for a way to fix all those issues more reliably. We'll bring more details here as soon as we have some results.
Updated•1 year ago
|
Updated•1 year ago
|
Comment 13•1 year ago
|
||
Polly: did your fix for bug 1892296 also fix this one? They look like they're the same bug, although the movie in the newer bug that you fixed was slightly more convincing.
Assignee | ||
Comment 14•1 year ago
|
||
Unfortunately i think https://bugzilla.mozilla.org/show_bug.cgi?id=1892296 was only a partial fix. This bug has a subtly different timing sequence which means it is still an issue. (I retested this in ff v128 to check).
Assignee | ||
Updated•1 year ago
|
Assignee | ||
Comment 15•1 year ago
|
||
i've retested this in the nightly (v130.0a1) and it looks like the fix for 1902996 has also resolved this.
Updated•1 year ago
|
Updated•1 year ago
|
Updated•1 year ago
|
Comment 16•1 year ago
|
||
This bug will be referenced in the advisory for the fix (bug 1902996)
Updated•7 months ago
|
Description
•