Closed Bug 1881902 Opened 1 year ago Closed 11 months ago

Permission Dialog allows to conduct Full Screen Spoof attack without notification on Android Firefox Nightly

Categories

(Fenix :: General, defect)

defect

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 1871217

People

(Reporter: proof131072, Unassigned, NeedInfo)

Details

(Keywords: csectype-spoof, reporter-external, sec-moderate, Whiteboard: [reporter-external] [client-bounty-form] [verif?])

Attachments

(5 files)

We can launch Permission Dialog such as camera, as soon as user enter to full screen mode resulting to hiding notification with full spoof.

  • Steps to reproduce:

Open https://pwning.click/camfullnoti.php and tap on "CLICK TO PLAY" which will reproduce this bug.

  • How to fix this issue

Let's check what Android Chrome does: Android Chrome would immediately exit full screen mode if any permission was requested and this is the ideal behaviour we want to see from Nightly.

Flags: sec-bounty?
Group: firefox-core-security → mobile-core-security
Component: Security → General
Product: Firefox → Fenix

(In reply to James Lee from comment #0)

  • How to fix this issue

Let's check what Android Chrome does: Android Chrome would immediately exit full screen mode if any permission was requested and this is the ideal behaviour we want to see from Nightly.

Alternatively, we could show the notification above the permission dialog which is what Android Opera GX is doing.

Attached file camloc.html

Here are all needed files if you want to test on your server.

Attached file camaccess.html
Attached file getcam.js

This prompt comes from the OS itself and for most permissions is only asked once, ever (unless the user chooses "only this time"). Sadly that means the more cautious/careful users are more at risk from this spoof than most other folks.

The severity field is not set for this bug.
:bclark, could you have a look please?

For more information, please visit BugBot documentation.

Flags: needinfo?(brclark)
Status: NEW → RESOLVED
Closed: 11 months ago
Duplicate of bug: 1871217
Resolution: --- → DUPLICATE
Flags: sec-bounty? → sec-bounty-
Group: mobile-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: