Address bar spoof ios show blank
Categories
(Firefox for iOS :: Browser, defect)
Tracking
()
Tracking | Status | |
---|---|---|
fxios | 133 | --- |
People
(Reporter: mrnoob790, Unassigned)
Details
(Keywords: csectype-spoof, reporter-external, sec-moderate, Whiteboard: [client-bounty-form])
Attachments
(2 files, 1 obsolete file)
Hi there is a issue where am able to send the user from a link to no url even about:blank not showing on adress bar
Go to mrnoob790.github.io/blank.html
There is a button iff u hold it u will see the website url but just click it and u will see no url on adress bar but the page is still there
Comment hidden (obsolete) |
Updated•11 months ago
|
Updated•10 months ago
|
Comment 2•10 months ago
|
||
Thanks daniel for attach the poc file .i forgot to attach the html file
Comment 4•10 months ago
|
||
Your PoC doesn't even execute because markdown ate your quotes. Please actually attach testcases, don't write them in contents where no one can execute them and they might have formatting issues. (plus they might be wrong)
Comment 5•10 months ago
|
||
Updated•10 months ago
|
Comment 6•10 months ago
|
||
We used to show literal "about:blank" for an about:blank window (see bug 1738053). I guess we fixed that for empty windows (which we the spec says we should but then STILL didn't fix the the important part which was updating the URLto be the origin of the scripting context if the contents were changed.
Blank is worse than the original "about:blank" problem <facepalm>
Can anyone please confirm: the vulnerability here is that the user is redirected to a potentially malicious page and the URL in the address bar is not correctly being updated (it is remaining blank), is that correct?
Comment hidden (obsolete) |
Comment 11•10 months ago
|
||
Note: tracking with Jira https://mozilla-hub.atlassian.net/browse/FXIOS-9483
Reporter | ||
Comment 12•10 months ago
|
||
(In reply to mreagan from comment #11)
Note: tracking with Jira https://mozilla-hub.atlassian.net/browse/FXIOS-9483
Should i can also join ? There
Reporter | ||
Comment 13•10 months ago
|
||
(In reply to Daniel Veditz [:dveditz] from comment #6)
We used to show literal "about:blank" for an about:blank window (see bug 1738053). I guess we fixed that for empty windows (which we the spec says we should but then STILL didn't fix the the important part which was updating the URLto be the origin of the scripting context if the contents were changed.
Blank is worse than the original "about:blank" problem <facepalm>
Yes i seen these issues in brave
Your adress bar show blank and when u click on adress bar its show about:blank.
Reporter | ||
Comment 14•10 months ago
|
||
Is that bug confirmed ...?
Comment hidden (duplicate) |
Comment hidden (duplicate) |
Comment 17•9 months ago
|
||
This issue may be addressed as part of forthcoming work to update the toolbar in the iOS client. I reached out to the relevant team members to confirm if we have an ETA on the fix (or whether this should potentially be addressed separately before then).
Reporter | ||
Comment 18•9 months ago
|
||
Thanks for the update i hope it will fix fast
Reporter | ||
Comment 19•8 months ago
|
||
Did u got reply from team when will its fix or ship
Comment 20•8 months ago
|
||
Following up again to find out if this will be addressed by the current toolbar work happening in the iOS client.
Comment hidden (offtopic) |
Comment hidden (duplicate) |
Reporter | ||
Comment 23•8 months ago
|
||
Hi @mreagan did u got any update from dev team when will these patched ?
Comment 24•8 months ago
|
||
It doesn't look like this will be addressed by the forthcoming iOS toolbar updates, I'm reaching out again to the team to double-check on when this can be prioritized.
Reporter | ||
Comment 25•8 months ago
|
||
Why its taking time 😅 i reported one bug in chrome in same timeline when i reported these and that bug is low priority issue bug its fixed realeased got bounty everything privious month and these one still there
Reporter | ||
Comment 26•7 months ago
|
||
Hey @mregan any update
Comment 27•7 months ago
|
||
@bharat I'm reaching out to the iOS team again to see if we have any available engineers to investigate the fix here.
Reporter | ||
Comment 28•7 months ago
|
||
@mregan did u recive any update from engineers team
Comment 29•7 months ago
|
||
@bharat Yes the ticket is currently being investigated by iOS engineering. As soon as we have any additional updates we'll be sure to post here.
Reporter | ||
Comment 30•7 months ago
|
||
So finally these one will be fixed
Comment 31•7 months ago
•
|
||
Hi, was looking into this and was wondering is the main issue that you see a blank page or the fact that its opening a link after 500MS?
Is the idea that when a user taps on the link they shouldn't be seeing the evil website? (just double checking here)
Edit: I also see that you mention there is no url in the urlbar but is that for legit website or your evil website?
Asking all these questions so I understand the complexity of the bug here.
Thanks
Reporter | ||
Comment 32•7 months ago
|
||
Hi So u will see when u go to blank.html there is click me buttom iff u hold it it will show its open legit web and when u click it it open blank url spoof page yes its mine website page .
Reporter | ||
Comment 33•7 months ago
|
||
I mean that blank url page is mine website page its need to show about:blank
Comment 34•7 months ago
•
|
||
Yes I see the blank page (legitwebsite link) but whats the issue?
a) Is it the fact that the url bar is not updated?
b) Is it opening another evil page?
or its both?
Reporter | ||
Comment 36•7 months ago
|
||
If u see these in firefox desktop u will see that evil page url will show my website where victim will know its open my website page
Reporter | ||
Comment 37•7 months ago
|
||
@nishant bhasin check in chrome ios u will see it will not open that blank adressbar page
Comment hidden (duplicate) |
Comment hidden (duplicate) |
Comment hidden (offtopic) |
Comment hidden (duplicate) |
Comment 42•6 months ago
|
||
Verified as fixed on v133 (47401) with iPhone 15 Pro (18.2).
Here is a video showing that when clicking on the button it redirects correctly to the website.
Updated•6 months ago
|
Reporter | ||
Comment 43•6 months ago
|
||
Hi yes i just tried v133 beta its fixed now .
Reporter | ||
Comment 44•6 months ago
|
||
Hi when will be bounty and cve announced ?
Comment 45•6 months ago
|
||
Hi Bharat, for any questions involving bounties you'll want to email security@mozilla.org. The CVE should be available a bit closer to the v133 RC release date.
Updated•6 months ago
|
Comment hidden (offtopic) |
Comment hidden (offtopic) |
Comment hidden (offtopic) |
Comment hidden (offtopic) |
Reporter | ||
Comment 50•6 months ago
|
||
Okk
Comment 51•6 months ago
|
||
Reporter | ||
Comment 52•6 months ago
|
||
Comment on attachment 9439771 [details]
advisory.txt
Please use Bharat(mrnoob) dont use adhikari
Updated•6 months ago
|
Updated•21 days ago
|
Description
•