Closed Bug 1877820 Opened 1 years ago Closed 1 year ago

Changing screen.orientation hides Full Screen Notification in Firefox Android

Categories

(Firefox for Android :: General, defect, P2)

defect

Tracking

()

RESOLVED FIXED
130 Branch
Tracking Status
firefox128 --- wontfix
firefox129 --- wontfix
firefox130 --- fixed

People

(Reporter: Puf, Assigned: polly)

References

Details

(Keywords: csectype-spoof, reporter-external, sec-moderate, Whiteboard: [client-bounty-form][adv-main130-])

Attachments

(3 files)

Attached file PufIndex.html

Hide Full Screen Notification in Firefox Android Using mailto:
Using Android Intent Link, We Can Hide Full Screen Notification in Firefox Android  
The Intent App Selection Open With & Then it Moves to Full Screen Mode & Turns to landscape screen.orientation

POC Video Private Unlisted : https://www.youtube.com/shorts/mXopnhbh9Q8

Firefox Version: [124.0a1 (Build #2016000647)]
Operating System: [Android 13]

Steps to Reproduce:

  1. Host PufIndex.Html In HTTP Server
  2. Now Visit the Page Click On [Click Me] Button
  3. Open in another app = Now Click On [OPEN]
    4.Success

I Have Attached POC Video Please Check It Out
Please Let Me Know If You Have Any Questions
Thank You

Flags: sec-bounty?
Group: firefox-core-security → mobile-core-security
Component: Security → General
Product: Firefox → Fenix

First It Will Open Apps Selection Dialog, After it will Immediately Enter into FullScreen Mode and then it Turns to landscape screen.orientation
The Fullscreen Notification Hides Behind Apps Selection Dialog. screen.orientation Change landscape to portrait Immediately This Makes User to Delay in Choosing Selection App

Status: UNCONFIRMED → NEW
Ever confirmed: true
Severity: -- → S3
Priority: -- → P2
Summary: Hide Full Screen Notification in Firefox Android → Changing screen.orientation hides Full Screen Notification in Firefox Android

I Would Like to Clarify Here
Full Screen Notification Hides Behind OPEN WITH Apps Selection Dialog
Changing screen.orientation Does not Hide Full Screen Notification
Thank You

Attached file PufIndex.html

Full Screen Notification Hides Behind System App Intent Selection Dialog

New POC Video Private Unlisted: https://www.youtube.com/shorts/fNaWroL4mB0
Steps to Reproduce:

  1. Open PufNew.html
  2. Double Tap Me > On Button
  3. Image Selection Dialog Shows It Hides Fullscreen Notification
  4. Done
Attached image Puf Explain.png

Two Types of Attacking Techniques in this Vulnerability

  1. Double tap on Screen can potentially hide the full-screen toast Using file Select Dialog in Android Which Leads Spoofing

  2. in Another Way Attacker Can Use this vulnerability for Stealing Images by Changing Background to http://www.google.com Page Screenshot While It's on Fullscreen Mode & it Does not Show full-screen toast, User thinks it's On Real page http://www.google.com Which Leads to Upload Images

I think severity should be Sec-High Please Verify Once again. Thank you!

Verified Testing! Looks like this vulnerability is fixed! in latest Firefox nightly version
Please Verify and Change Status to fixed

Thank you!

Flags: needinfo?(polly)
Depends on: CVE-2024-8388
Flags: needinfo?(polly)

yes, i agree - have retested in latest nightly (130.0.a1) and looks like this is now fixed! thanks for the heads up :)

Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Assignee: nobody → polly
Group: mobile-core-security → core-security-release
Target Milestone: --- → 130 Branch
Flags: sec-bounty?
Flags: sec-bounty+
Flags: needinfo?(dveditz)

This bug will be referenced in the advisory for the fix (bug 1902996)

Whiteboard: [reporter-external] [client-bounty-form] [verif?] → [client-bounty-form][adv-main130-]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: