the autofill prompt remains on top of the new page after a new tab opens under it
Categories
(Toolkit :: Form Autofill, defect)
Tracking
()
People
(Reporter: sas.kunz, Assigned: dimi)
References
Details
(Keywords: csectype-spoof, reporter-external, sec-low, Whiteboard: [client-bounty-form][adv-main151+][adv-esr140.11+])
Attachments
(6 files)
|
1.88 MB,
video/mp4
|
Details | |
|
2.36 KB,
text/html
|
Details | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
phab-bot
:
approval-mozilla-beta+
|
Details | Review |
|
48 bytes,
text/x-phabricator-request
|
phab-bot
:
approval-mozilla-esr140+
|
Details | Review |
|
5.35 MB,
video/quicktime
|
Details |
I found a vulnerability where autofill prompts across to other origin when moving tabs using the down button
steps to reproduces:
- open
2.click the button
3.back to first tab - hold down button for 2 seconds
Firefox version: 139.0a1 (2025-04-23) (64-bit) Nightly
OS: WIndows 11
steps to reproduces:
- open test.html
- click the button
- back to first tab
- hold down button for 2 seconds
Comment 3•1 year ago
|
||
Not so easy to reproduce on Mac, but once the credit card prompt opens I can switch tabs at will and the overlay bleeds through to all of them.
Clearly wrong and broken, but clearly this set of instructions are not a viable spoof. Maybe there's something that could come of it though.
Comment 4•1 year ago
|
||
FWIW I think fixing this might be as easy as adding tabspecific="true" on https://searchfox.org/mozilla-central/rev/4c065f1df299065c305fb48b36cdae571a43d97c/browser/base/content/main-popupset.inc.xhtml#128-136 .
Comment 5•1 year ago
|
||
The severity field is not set for this bug.
:dimi, could you have a look please?
For more information, please visit BugBot documentation.
| Assignee | ||
Comment 6•4 months ago
|
||
Updated•4 months ago
|
| Assignee | ||
Updated•4 months ago
|
Comment 8•4 months ago
|
||
https://hg.mozilla.org/mozilla-central/rev/c06fcc867238
Please nominate this for Beta and ESR140 uplift when you get a chance.
Comment 9•4 months ago
|
||
firefox-beta Uplift Approval Request
- User impact if declined/Reason for urgency: Autofill dropdown stays painted on top of other tabs (including different-origin tabs) after a tab switch.
- Code covered by automated testing?: no
- Fix verified in Nightly?: no
- Needs manual QE testing?: no
- Steps to reproduce for manual QE testing: Follow https://bugzilla.mozilla.org/show_bug.cgi?id=1962625#c2
- Risk associated with taking this patch: low
- Explanation of risk level: One-line XHTML change adding the existing locationspecific="true" attribute to PopupAutoComplete. Opts into established XUL panel behavior already used by other tab-scoped popups. No JS or platform code touched.
- String changes made/needed?: None.
- Is Android affected?: no
| Assignee | ||
Comment 10•4 months ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D299380
Comment 11•4 months ago
|
||
firefox-esr140 Uplift Approval Request
- User impact if declined/Reason for urgency: Autofill dropdown stays painted on top of other tabs (including different-origin tabs) after a tab switch.
- Code covered by automated testing?: no
- Fix verified in Nightly?: no
- Needs manual QE testing?: no
- Steps to reproduce for manual QE testing: Follow https://bugzilla.mozilla.org/show_bug.cgi?id=1962625#c2
- Risk associated with taking this patch: low
- Explanation of risk level: One-line XHTML change adding the existing locationspecific="true" attribute to PopupAutoComplete. Opts into established XUL panel behavior already used by other tab-scoped popups. No JS or platform code touched.
- String changes made/needed?: None.
- Is Android affected?: no
| Assignee | ||
Comment 12•4 months ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D299380
| Assignee | ||
Updated•4 months ago
|
Updated•4 months ago
|
Updated•4 months ago
|
Updated•4 months ago
|
Comment 13•4 months ago
|
||
| uplift | ||
Updated•4 months ago
|
Updated•4 months ago
|
Comment 14•4 months ago
|
||
I reproduced the initial issue on Firefox 150.0.3 on Windows 11, where the autofill prompt is displayed on the second tab after holding the Down button on the test.html tab (the first tab).
Verified as fixed using the latest Nightly 152.0a1 (Build ID: 20260513205207) on Windows 11, Ubuntu 24.04 and macOS 26.4 - the autofill prompt is not visible on either the second tab or on the test.html tab.
However, while I can no longer reproduce the issue on Firefox 151 (Build ID: 20260513195118) on Windows 11, where the autofill prompt no longer appears, I'm still seeing the autofill prompt on the test.html page on macOS 26.4 ,as well as a brief glimpse of it on Ubuntu 24 (right before the focus moves from the test.html page to the other tab after holding the Down button). I'm attaching a screen recording from macOS for more details.
@Dimi, could you please take a look? Is this expected behavior?
Updated•4 months ago
|
Updated•4 months ago
|
Updated•4 months ago
|
Comment 15•4 months ago
|
||
| uplift | ||
Comment 16•4 months ago
|
||
Tested also on Firefox 140 ESR using a Treeherder build (Build ID: 20260514160037), and I see the same behavior as on Firefox 151 - tested on Windows 11, macOS 14 and Ubuntu 24.04. The autofill prompt does not remain on top of the new page, but it is still visible in the first tab where the test.html page is loaded - visible on all 3 OS'es.
Waiting for a confirmation, as I'm not sure whether this is expected behavior or if a new bug should be filed for it.
Updated•4 months ago
|
Updated•4 months ago
|
Comment 17•4 months ago
|
||
I confirmed with Dimi via Slack that the behavior I was seeing is expected. Marking this as verified on firefox-esr140 and firefox151.
| Assignee | ||
Updated•4 months ago
|
Updated•4 months ago
|
Comment 18•4 months ago
|
||
Because this bug was filed before we changed the spoofing bounty requirements, it is evaluated under the old policy and paid comparatively.
Updated•4 months ago
|
Updated•1 month ago
|
Description
•