Clickjacking with Long Prompt allows to take over camera, microphone and other permissions on Android Firefox Nightly
Categories
(Firefox for Android :: Browser Engine, defect)
Tracking
()
People
(Reporter: proof131072, Unassigned)
Details
(4 keywords, Whiteboard: [reporter-external] [client-bounty-form] [verif?])
Attachments
(4 files)
Android FIrefox Nightly lets Long Prompt to obscure permission prompt resulting to take over camera, microphone and other permissions.
We'll open permission prompt first and then launch Long Prompt immediately to make this work and there are two or more attack cases.
- User confirming prompt notification twice to close them with no delay: https://pwning.click/clickjacker.php (or attached case1.html)
Users confirming prompt to close them resulting to take over camera permission, all records and screenshots will be sent to attacker's server.
- Multiple prompt notification leading users to repeatedly confirm the prompts to close all of them resulting to take over camera permission, all records and screenshots will be sent to attacker's server.
Updated•2 years ago
|
Comment 2•2 years ago
|
||
Why would someone double-click a button, even if you do ask nicely in your prompt?
That's where case 2 comes in, which raises the severity since users "have to" spam click confirm all long prompts to continue to the page with the game they want to play which will automatically allow camera permission. We can not check the block popup dialog tick straightly for long enough prompt.
Comment 4•2 years ago
|
||
The severity field is not set for this bug.
:bclark, could you have a look please?
For more information, please visit BugBot documentation.
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Hi, we can close this report.
This has been fixed by the fix for Bug 1908344 and unfortunately, I knew the behaviour that select options (and safe permission prompt too, actually.) could've obscured permission prompts on Nightly and Focus; which I didn't report them since I thought they were duplicate to this report.
But even without those two different ways to obscure permission prompts, this report is misunderstood; I provided case 2 on comment 3 where we'll have a game loading dialog which is possible to trigger from Full Screen game with loading status, "...Loading... 10%" and the next dialog is "...Loading... 20%", "...Loading... 30%" next and so on where users will be naturally lured into confirming game loading dialogs and end up allowing camera permission, which I believe is high end sec-moderate or possibly low end sec-high like Bug 1908344 since user can only play this game when game loading dialogs are confirmed as users' willing.
Updated•1 month ago
|
Updated•1 month ago
|
Updated•1 month ago
|
Description
•