Closed Bug 1872601 (CVE-2025-11717) Opened 2 years ago Closed 10 months ago

The screen to edit a password is not hidden is recent app list and, at least, can be used for a screenshot

Categories

(Firefox for Android :: Logins, defect)

All
Android
defect

Tracking

()

VERIFIED FIXED
145 Branch
Tracking Status
firefox143 --- wontfix
firefox144 + verified
firefox145 + verified

People

(Reporter: msd+bugzilla, Assigned: avirvara)

Details

(Keywords: csectype-disclosure, reporter-external, sec-moderate, Whiteboard: [group1][adv-main144+])

Attachments

(4 files)

Attached image 1.png

Steps to reproduce

  1. Go to parameters > Id and Passwords > Recorded Id > give access with schema > Edit a field
  2. Display the password by clicking on the eye icon
  3. Go back to the home screen
  4. In the recent screen app the URL, ID and password is displayed

Expected behavior

Like in private navigation mode, it is impossible to see a thumbnail of the screen in the Android recent app list and it is impossible to make a screenshot of this window.

Actual behavior

The password is displayed in the Android recent app list and I can make a screenshot of this window.

Device information

  • Firefox version: 121.0.0
  • Android device model: Samsung Galaxy S5
  • Android OS version: 11

Note: the list of sites and passwords before you choose one to edit is blanked out in the app-card display, as is the page that displays a single username/password. It's specifically the "Edit a password" screen that is not protected.

I'm sorry, I reproduced it incorrectly. I see the same behavior for the individual password display screen. If you go into card view from either of those pages it is correctly blank, but if you go from that page to the phone's homescreen and -then- view the cards the data will be shown.

When you select the card you are correctly bumped back to the screen where you have to choose "saved logins" and present your biometrics or passwords.

Severity: -- → S3
Priority: -- → P2

Clearing Priority so we can reprioritize these bugs relative to our ux-fun-2024 bugs.

Priority: P2 → --

Sorry for the burst of bugspam: filter on tinkling-glitter-filtrate
Adding reporter-external keyword to security bugs found by non-employees for accounting reasons

Hi Jeff, can your squad take this as their current sec bug? We are trying to catch up on some that fell through the cracks

Flags: needinfo?(jboek)
Whiteboard: [group1]

Just added it to our backlog to pull in next sprint.

Flags: needinfo?(jboek)
Attached file (secure)
Assignee: nobody → avirvara
Status: NEW → ASSIGNED
Pushed by amarc@mozilla.com: https://github.com/mozilla-firefox/firefox/commit/290fc9466ac0 https://hg.mozilla.org/mozilla-central/rev/84c402310a23 hide sensitive content of logins screens when in background r=android-reviewers,boek
Group: mobile-core-security → core-security-release
Status: ASSIGNED → RESOLVED
Closed: 10 months ago
Resolution: --- → FIXED
Target Milestone: --- → 145 Branch

Alexandra, please add a beta uplift request when you have a moment.

Flags: needinfo?(avirvara)

Comment on attachment 9513588 [details]
(secure)

Beta/Release Uplift Approval Request

  • User impact if declined/Reason for urgency: the fix helps hiding some sensitive information in logins screen (compose version)
  • Is this code covered by automated tests?: No
  • Has the fix been verified in Nightly?: No
  • Needs manual test from QE?: Yes
  • If yes, steps to reproduce: Go to Secret settings & enable compose logins
    Go to logins screen -> details screen -> edit screen or just enter add password screen.
    Send app in backround
    Observe the screen
  • List of other uplifts needed: None
  • Risk to taking this patch: Low
  • Why is the change risky/not risky? (and alternatives if risky): The fix adds a secure flag that doesn't allow taking screenshots of the current screen and doesn't allow seeing the screen content while the app is on background
  • String changes made/needed:
  • Is Android affected?: Yes
Flags: needinfo?(avirvara)
Attachment #9513588 - Flags: approval-mozilla-beta?
Flags: qe-verify+

Comment on attachment 9513588 [details]
(secure)

Approved for 144.0b4

Attachment #9513588 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
Attached image 1872601.jpg

Verified as fixed on the latest Firefox for Android Nightly 145.0a1 from 9/24, and on Firefox for Android Beta 144.0b4 using a Samsung Galaxy S24 (Android 15).

Status: RESOLVED → VERIFIED
Flags: qe-verify+
Whiteboard: [group1] → [group1][adv-main144+]
Attached file advisory.txt
Alias: CVE-2025-11717
Flags: sec-bounty?
Flags: sec-bounty? → sec-bounty+
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: