Closed Bug 1935842 Opened 1 year ago Closed 2 months ago

Wrong AAGUID on macos with cross-platform attachment when using Android phone (Google password manager) to create a passkey

Categories

(Core :: DOM: Web Authentication, defect, P2)

Firefox 133
defect

Tracking

()

RESOLVED FIXED
153 Branch
Tracking Status
firefox153 --- fixed

People

(Reporter: nripendra.newa, Assigned: jschanck)

Details

Attachments

(2 files)

User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:133.0) Gecko/20100101 Firefox/133.0

Steps to reproduce:

Register a passkey on macos with cross-platform attachment, and use android phone (which uses Google password manager) to create a passkey.

Actual results:

When parsing the PublicKeyCredential generated on the server, the AAGUID is set to all zeros.

Expected results:

Set the correct AAGUID of the authenticator. All other major browsers Safari, Chrome, Edge is resolving to correct AAGUID that belongs to the Google password manager.

The Bugbug bot thinks this bug should belong to the 'Core::Widget: Cocoa' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.

Component: Untriaged → Widget: Cocoa
Product: Firefox → Core

The severity field is not set for this bug.
:spohl, could you have a look please?

For more information, please visit BugBot documentation.

Flags: needinfo?(spohl.mozilla.bugs)
Severity: -- → S3
Flags: needinfo?(spohl.mozilla.bugs)
Priority: -- → P3

Same issue with Firefox on Android with Bitwarden. Tried from Firefox 139 all the way to Firefox 147 beta. Same issue.

I observed this behavior on both webauthn.io and amazon.ca.

I added a screenshot. As you can see, webauthn.io thinks i'm using iCloud Keychain because of the invalid AAGUID. Same thing on amazon.ca

I saw an old reddit post that said to put the attestation in direct mode in webauthn.io. They said it worked for them on Google Chrome.

This bug seems to be different as using direct mode in the webauthn.io advanced registration settings does not fix this.

@Stephen: Would it be possible to reprioritize this bug?

This bug makes passkeys implementation look flimzy and unreliable. This was enough to stop me from using passkeys for the past year. I understand it might seem like a cosmetic problem but i think that this bug could hinder trust and delay passwordless adoption for users like me.

Flags: needinfo?(spohl.mozilla.bugs)
Component: Widget: Cocoa → DOM: Web Authentication
Flags: needinfo?(spohl.mozilla.bugs)

This issue is still present on Android for the latest Firefox (149/150.0b2) and Bitwarden(2026.3.0).

Are we missing information/something to get this bug confirmed and assigned?

Flags: needinfo?(jschanck)
Assignee: nobody → jschanck
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Flags: needinfo?(jschanck)
Priority: P3 → P2
No longer duplicate of this bug: 2046255
No longer duplicate of this bug: 2046244
Status: ASSIGNED → RESOLVED
Closed: 2 months ago
Resolution: --- → FIXED
Target Milestone: --- → 153 Branch
QA Whiteboard: [qa-triage-done-c154/b153]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: