Closed
Bug 1952154
Opened 1 month ago
Closed 1 month ago
[Android] Firefox http auth spoof
Categories
(Firefox for Android :: General, defect)
Firefox for Android
General
Tracking
()
RESOLVED
DUPLICATE
of bug 1631073
People
(Reporter: ameenbasha111, Unassigned)
References
Details
(Keywords: csectype-spoof, reporter-external, Whiteboard: [client-bounty-form])
Attachments
(2 files)
HI Team, Firefox latest version on android is vulnerable for this auth spoof vulnerability which displays the http basic auth bar on the wrong domain
Steps to reproduce
- Host the attached html
- Click the button, You can see the basic auth is displayed on google domain
Note: issue already fixed on chrome ios
Ref: https://issues.chromium.org/issues/40055876
Flags: sec-bounty?
Reporter | ||
Comment 1•1 month ago
|
||
Updated•1 month ago
|
Group: firefox-core-security → mobile-core-security
Component: Security → General
Keywords: csectype-spoof,
dupeme
Product: Firefox → Fenix
See Also: → https://issues.chromium.org/issues/40055876
Updated•1 month ago
|
Status: UNCONFIRMED → RESOLVED
Closed: 1 month ago
Duplicate of bug: 1631073
Resolution: --- → DUPLICATE
Comment hidden (obsolete) |
Reporter | ||
Comment 4•1 month ago
|
||
the duplicated parent issue was opened for 5 long years, do we have any plan to initiate fix with respect to this ticket?
Updated•1 month ago
|
Group: mobile-core-security
Updated•29 days ago
|
Flags: sec-bounty? → sec-bounty-
You need to log in
before you can comment on or make changes to this bug.
Description
•