Date picker is Able to Overlap Fullscreen Notification
Categories
(Core :: DOM: Core & HTML, defect)
Tracking
()
People
(Reporter: fazim.pentester, Assigned: canadahonk)
Details
(Keywords: csectype-spoof, reporter-external, sec-low, Whiteboard: [reporter-external] [client-bounty-form] [verif?])
Attachments
(3 files)
By utilizing the Date picker, Firefox fullscreen notifications can be obscured. Below is a proof of concept where the attacker site requests the user to click to launching the Date picker above the fullscreen notification and thereby spoofing the browser.
Steps to Reproduce:
- Download the poc.html file.
- Open the poc.html file in firefox for testing.
Reporter | ||
Comment 1•1 year ago
|
||
Updated•1 year ago
|
Comment 2•1 year ago
|
||
It's not great that we let things float on top of that banner generally, but this widget doesn't obscure what is happening
Reporter | ||
Comment 3•1 year ago
|
||
Covers the part of the text fullscreen neatly. If possible to launch 2 similar widgets together, could completely cover the banner, but I am not sure if it's possible.
Comment 4•1 year ago
|
||
The severity field is not set for this bug.
:edgar, could you have a look please?
For more information, please visit BugBot documentation.
Comment 5•1 year ago
|
||
I think this case could be fixed after bug 1877969.
(Set severity to S2 as bug 1877969 is S2)
Updated•11 months ago
|
Comment 6•11 months ago
|
||
Moving to S3 per the security rating for this particular case. We will revisit and verify this after the S2 bug 1877969.
Reporter | ||
Comment 7•9 months ago
|
||
Hi Dan,
It seems this issue is fixed by Bug 1903187 (just saw it in the advisory). I don't mind duplicating it into that issue, but I would like to know if this qualifies for a bounty and if we can also classify it as sec-medium since the similar bug is also sec-medium.
Reporter | ||
Comment 8•9 months ago
|
||
(Canceling previous comment. Not the same issue. It seems this issue is fixed.)
Hi Hasin-Yi,
Can you verify if this issue is fixed? Thank you.
Reporter | ||
Comment 9•9 months ago
|
||
Tested on the latest nightly version 131.0a1 (2024-08-06) (64-bit) on Windows 11.
Comment 10•9 months ago
|
||
(In reply to Shaheen Fazim from comment #9)
Created attachment 9418113 [details]
test-1876595.mp4Tested on the latest nightly version 131.0a1 (2024-08-06) (64-bit) on Windows 11.
I verify that I saw the same behavior on my Windows 11 machine, when using Nightly 131. The issue is fixed. Thank you.
Updated•8 months ago
|
Updated•8 months ago
|
Updated•8 months ago
|
Updated•8 months ago
|
Updated•2 months ago
|
Updated•2 months ago
|
Updated•1 month ago
|
Description
•