Closed Bug 1905749 (CVE-2024-53976) Opened 11 months ago Closed 6 months ago

Address bar spoof ios show blank

Categories

(Firefox for iOS :: Browser, defect)

defect

Tracking

()

VERIFIED FIXED
Tracking Status
fxios 133 ---

People

(Reporter: mrnoob790, Unassigned)

Details

(Keywords: csectype-spoof, reporter-external, sec-moderate, Whiteboard: [client-bounty-form])

Attachments

(2 files, 1 obsolete file)

Hi there is a issue where am able to send the user from a link to no url even about:blank not showing on adress bar
Go to mrnoob790.github.io/blank.html
There is a button iff u hold it u will see the website url but just click it and u will see no url on adress bar but the page is still there

Flags: sec-bounty?
Group: firefox-core-security → mobile-core-security
Component: Security → Browser
Product: Firefox → Firefox for iOS
Summary: Adress bar spoof ios show blank → Address bar spoof ios show blank
Attached file poc.html (obsolete) —

Thanks daniel for attach the poc file .i forgot to attach the html file

Your PoC doesn't even execute because markdown ate your quotes. Please actually attach testcases, don't write them in contents where no one can execute them and they might have formatting issues. (plus they might be wrong)

Attached file poc-redux.html
Attachment #9411147 - Attachment is obsolete: true
Attachment #9411148 - Attachment mime type: text/plain → text/html

We used to show literal "about:blank" for an about:blank window (see bug 1738053). I guess we fixed that for empty windows (which we the spec says we should but then STILL didn't fix the the important part which was updating the URLto be the origin of the scripting context if the contents were changed.

Blank is worse than the original "about:blank" problem <facepalm>

Status: UNCONFIRMED → NEW
Ever confirmed: true

Waiting for the team to verify and fix the issue

Any update sir

Flags: needinfo?(dveditz)

Can anyone please confirm: the vulnerability here is that the user is redirected to a potentially malicious page and the URL in the address bar is not correctly being updated (it is remaining blank), is that correct?

(In reply to mreagan from comment #11)

Note: tracking with Jira https://mozilla-hub.atlassian.net/browse/FXIOS-9483

Should i can also join ? There

(In reply to Daniel Veditz [:dveditz] from comment #6)

We used to show literal "about:blank" for an about:blank window (see bug 1738053). I guess we fixed that for empty windows (which we the spec says we should but then STILL didn't fix the the important part which was updating the URLto be the origin of the scripting context if the contents were changed.

Blank is worse than the original "about:blank" problem <facepalm>

Yes i seen these issues in brave
Your adress bar show blank and when u click on adress bar its show about:blank.

Is that bug confirmed ...?

This issue may be addressed as part of forthcoming work to update the toolbar in the iOS client. I reached out to the relevant team members to confirm if we have an ETA on the fix (or whether this should potentially be addressed separately before then).

Flags: needinfo?(mreagan)

Thanks for the update i hope it will fix fast

Did u got reply from team when will its fix or ship

Flags: needinfo?(mreagan)

Following up again to find out if this will be addressed by the current toolbar work happening in the iOS client.

Flags: needinfo?(mreagan)

Hi @mreagan did u got any update from dev team when will these patched ?

Flags: needinfo?(mreagan)

It doesn't look like this will be addressed by the forthcoming iOS toolbar updates, I'm reaching out again to the team to double-check on when this can be prioritized.

Flags: needinfo?(mreagan)

Why its taking time 😅 i reported one bug in chrome in same timeline when i reported these and that bug is low priority issue bug its fixed realeased got bounty everything privious month and these one still there

Hey @mregan any update

@bharat I'm reaching out to the iOS team again to see if we have any available engineers to investigate the fix here.

@mregan did u recive any update from engineers team

@bharat Yes the ticket is currently being investigated by iOS engineering. As soon as we have any additional updates we'll be sure to post here.

So finally these one will be fixed

Hi, was looking into this and was wondering is the main issue that you see a blank page or the fact that its opening a link after 500MS?
Is the idea that when a user taps on the link they shouldn't be seeing the evil website? (just double checking here)

Edit: I also see that you mention there is no url in the urlbar but is that for legit website or your evil website?

Asking all these questions so I understand the complexity of the bug here.

Thanks

Flags: needinfo?(mrnoob790)

Hi So u will see when u go to blank.html there is click me buttom iff u hold it it will show its open legit web and when u click it it open blank url spoof page yes its mine website page .

Flags: needinfo?(mrnoob790)

I mean that blank url page is mine website page its need to show about:blank

Yes I see the blank page (legitwebsite link) but whats the issue?

a) Is it the fact that the url bar is not updated?
b) Is it opening another evil page?

or its both?

Flags: needinfo?(mrnoob790)

Its both

Flags: needinfo?(mrnoob790)

If u see these in firefox desktop u will see that evil page url will show my website where victim will know its open my website page

@nishant bhasin check in chrome ios u will see it will not open that blank adressbar page

Verified as fixed on v133 (47401) with iPhone 15 Pro (18.2).
Here is a video showing that when clicking on the button it redirects correctly to the website.

Status: NEW → RESOLVED
Closed: 6 months ago
Resolution: --- → FIXED
Status: RESOLVED → VERIFIED

Hi yes i just tried v133 beta its fixed now .

Hi when will be bounty and cve announced ?

Flags: needinfo?(dveditz)
Flags: needinfo?(mreagan)

Hi Bharat, for any questions involving bounties you'll want to email security@mozilla.org. The CVE should be available a bit closer to the v133 RC release date.

Flags: needinfo?(mreagan)
Group: mobile-core-security → core-security-release

Okk

Attached file advisory.txt

Comment on attachment 9439771 [details]
advisory.txt

Please use Bharat(mrnoob) dont use adhikari

Alias: CVE-2024-53976
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: