Closed Bug 1883456 Opened 2 years ago Closed 2 years ago

WebAuthn API Can Hide Fullscreen Notifications on Android

Categories

(Firefox for Android :: General, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1865413

People

(Reporter: fazim.pentester, Unassigned)

Details

(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])

Attachments

(2 files)

Attached file poc.html

Using the Web Authentication API, a malicious site could hide Firefox's fullscreen notification toast on Android, potentially allowing it to spoof the browser by impersonating trusted sites with custom address bars.

Steps to Reproduce:

  1. Download and poc.html file
  2. Host a HTTPS server using the proof-of-concept file.
  3. Open the Android Firefox browser and navigate to the HTTPS server to Begin testing.
Flags: sec-bounty?
Group: firefox-core-security → core-security
Component: Security → DOM: Web Authentication
Product: Firefox → Core
Group: core-security → crypto-core-security

tthibaud, is this a dupe of bug 1865413? The description sounds the same but I didn't look at the test case.

Group: crypto-core-security → mobile-core-security
Component: DOM: Web Authentication → General
Flags: needinfo?(tthibaud)
Product: Core → Fenix

(In reply to Andrew McCreight [:mccr8] from comment #1)

tthibaud, is this a dupe of bug 1865413? The description sounds the same but I didn't look at the test case.

Kindly cc, Thanks

Attached video demo.mp4
Status: NEW → RESOLVED
Closed: 2 years ago
Duplicate of bug: 1865413
Resolution: --- → DUPLICATE
Flags: sec-bounty? → sec-bounty-
Flags: needinfo?(tthibaud)
Group: mobile-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: