Closed Bug 1870386 Opened 1 year ago Closed 1 year ago

firefox URI for iOS Firefox allows to load file URI

Categories

(Firefox for iOS :: General, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1870384

People

(Reporter: proof131072, Unassigned)

Details

(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])

We are able to load file URI through firefox URI. Just like I suggested for QR Code Scanning issue https://bugzilla.mozilla.org/show_bug.cgi?id=1868005#c5 firefox URI should only allow http/https.

firefox://open-url?url=file:/

Flags: sec-bounty?
Group: firefox-core-security → mobile-core-security
Component: Security → General
Product: Firefox → Firefox for iOS
See Also: → CVE-2024-26281
Status: NEW → RESOLVED
Closed: 1 year ago
Duplicate of bug: 1870384
Resolution: --- → DUPLICATE
See Also: CVE-2024-26281
Flags: sec-bounty? → sec-bounty-
Group: mobile-core-security
You need to log in before you can comment on or make changes to this bug.