Closed Bug 1962625 (CVE-2026-8961) Opened 1 year ago Closed 4 months ago

the autofill prompt remains on top of the new page after a new tab opens under it

Categories

(Toolkit :: Form Autofill, defect)

defect

Tracking

()

VERIFIED FIXED
152 Branch
Tracking Status
firefox-esr115 --- wontfix
firefox-esr140 151+ verified
firefox150 --- wontfix
firefox151 + verified
firefox152 + verified

People

(Reporter: sas.kunz, Assigned: dimi)

References

Details

(Keywords: csectype-spoof, reporter-external, sec-low, Whiteboard: [client-bounty-form][adv-main151+][adv-esr140.11+])

Attachments

(6 files)

I found a vulnerability where autofill prompts across to other origin when moving tabs using the down button

steps to reproduces:

  1. open
    2.click the button
    3.back to first tab
  2. hold down button for 2 seconds

Firefox version: 139.0a1 (2025-04-23) (64-bit) Nightly
OS: WIndows 11

Flags: sec-bounty?
Attached file test.html —

steps to reproduces:

  1. open test.html
  2. click the button
  3. back to first tab
  4. hold down button for 2 seconds

Not so easy to reproduce on Mac, but once the credit card prompt opens I can switch tabs at will and the overlay bleeds through to all of them.

Clearly wrong and broken, but clearly this set of instructions are not a viable spoof. Maybe there's something that could come of it though.

Component: Security → Form Autofill
Product: Firefox → Toolkit
See Also: → 1963301
Summary: the autofill prompt cross to other origin → the autofill prompt remains on top of the new page after a new tab opens under it

The severity field is not set for this bug.
:dimi, could you have a look please?

For more information, please visit BugBot documentation.

Flags: needinfo?(dlee)
Attached file (secure) —
Assignee: nobody → dlee
Status: NEW → ASSIGNED
Flags: needinfo?(dlee)

https://hg.mozilla.org/mozilla-central/rev/c06fcc867238

Please nominate this for Beta and ESR140 uplift when you get a chance.

Group: firefox-core-security → core-security-release
Status: ASSIGNED → RESOLVED
Closed: 4 months ago
Flags: needinfo?(dlee)
Resolution: --- → FIXED
Target Milestone: --- → 152 Branch

firefox-beta Uplift Approval Request

  • User impact if declined/Reason for urgency: Autofill dropdown stays painted on top of other tabs (including different-origin tabs) after a tab switch.
  • Code covered by automated testing?: no
  • Fix verified in Nightly?: no
  • Needs manual QE testing?: no
  • Steps to reproduce for manual QE testing: Follow https://bugzilla.mozilla.org/show_bug.cgi?id=1962625#c2
  • Risk associated with taking this patch: low
  • Explanation of risk level: One-line XHTML change adding the existing locationspecific="true" attribute to PopupAutoComplete. Opts into established XUL panel behavior already used by other tab-scoped popups. No JS or platform code touched.
  • String changes made/needed?: None.
  • Is Android affected?: no
Attachment #9585857 - Flags: approval-mozilla-beta?
Attached file (secure) —

firefox-esr140 Uplift Approval Request

  • User impact if declined/Reason for urgency: Autofill dropdown stays painted on top of other tabs (including different-origin tabs) after a tab switch.
  • Code covered by automated testing?: no
  • Fix verified in Nightly?: no
  • Needs manual QE testing?: no
  • Steps to reproduce for manual QE testing: Follow https://bugzilla.mozilla.org/show_bug.cgi?id=1962625#c2
  • Risk associated with taking this patch: low
  • Explanation of risk level: One-line XHTML change adding the existing locationspecific="true" attribute to PopupAutoComplete. Opts into established XUL panel behavior already used by other tab-scoped popups. No JS or platform code touched.
  • String changes made/needed?: None.
  • Is Android affected?: no
Attachment #9585858 - Flags: approval-mozilla-esr140?
Attached file (secure) —
Flags: needinfo?(dlee)
Attachment #9585857 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
QA Whiteboard: [sec] [uplift] [qa-ver-needed-c152/b151]
Flags: qe-verify+

I reproduced the initial issue on Firefox 150.0.3 on Windows 11, where the autofill prompt is displayed on the second tab after holding the Down button on the test.html tab (the first tab).

Verified as fixed using the latest Nightly 152.0a1 (Build ID: 20260513205207) on Windows 11, Ubuntu 24.04 and macOS 26.4 - the autofill prompt is not visible on either the second tab or on the test.html tab.

However, while I can no longer reproduce the issue on Firefox 151 (Build ID: 20260513195118) on Windows 11, where the autofill prompt no longer appears, I'm still seeing the autofill prompt on the test.html page on macOS 26.4 ,as well as a brief glimpse of it on Ubuntu 24 (right before the focus moves from the test.html page to the other tab after holding the Down button). I'm attaching a screen recording from macOS for more details.

@Dimi, could you please take a look? Is this expected behavior?

Flags: needinfo?(dlee)
Attachment #9585858 - Flags: approval-mozilla-esr140? → approval-mozilla-esr140+

Tested also on Firefox 140 ESR using a Treeherder build (Build ID: 20260514160037), and I see the same behavior as on Firefox 151 - tested on Windows 11, macOS 14 and Ubuntu 24.04. The autofill prompt does not remain on top of the new page, but it is still visible in the first tab where the test.html page is loaded - visible on all 3 OS'es.

Waiting for a confirmation, as I'm not sure whether this is expected behavior or if a new bug should be filed for it.

Whiteboard: [client-bounty-form] → [client-bounty-form][adv-main151+][adv-main151+][adv-esr115.36+][adv-esr115.36+][adv-esr140.11+][adv-esr140.11+]
Whiteboard: [client-bounty-form][adv-main151+][adv-main151+][adv-esr115.36+][adv-esr115.36+][adv-esr140.11+][adv-esr140.11+] → [client-bounty-form][adv-main151+][adv-esr140.11+]

I confirmed with Dimi via Slack that the behavior I was seeing is expected. Marking this as verified on firefox-esr140 and firefox151.

Status: RESOLVED → VERIFIED
QA Whiteboard: [sec] [uplift] [qa-ver-needed-c152/b151] → [sec] [uplift] [qa-ver-done-c152/b151]
Flags: qe-verify+
Flags: needinfo?(dlee)
Flags: sec-bounty? → sec-bounty+
See Also: → CVE-2025-5267

Because this bug was filed before we changed the spoofing bounty requirements, it is evaluated under the old policy and paid comparatively.

Alias: CVE-2026-8961
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: