Closed Bug 1970997 (CVE-2025-8039) Opened 9 months ago Closed 9 months ago

sometimes the search term persists in the url bar

Categories

(Firefox :: Address Bar, defect, P2)

defect

Tracking

()

VERIFIED FIXED
141 Branch
Tracking Status
firefox-esr115 --- unaffected
firefox-esr128 --- unaffected
firefox-esr140 141+ verified
firefox140 --- wontfix
firefox141 --- verified
firefox142 --- verified

People

(Reporter: soeren.hentzschel, Assigned: jteow)

References

Details

(Keywords: csectype-spoof, reporter-external, sec-low, Whiteboard: [sng][adv-main141+][adv-ESR140.1+])

Attachments

(3 files, 1 obsolete file)

Attached image screenshot

if you look at the screenshot, you can see that the Google logo and the search term are in the address bar, even though a Non-Google website is loaded (it was the result of a Google search). Normally this should not happen, especially since it can also be seen as a security issue if the URL of an arbitrary website is not visible.

In most cases, the described behavior does not happen. However, this has now happened to me for the second time within a few days (on different devices each time).

Firefox Nightly 141.0a1 (2025-06-06) on macOS 15.5.

This is pretty bad from a security standpoint. James, would you be able to take a look?

Severity: -- → S2
Flags: needinfo?(jteow)
Priority: -- → P2

Thanks for flagging, I'll prioritize investigating this first thing next week.

Assignee: nobody → jteow
Whiteboard: [sng]

Unable to reproduce the original issue, but adding a safeguard
to ensure search terms only persist when the current URI matches
the URI that was used to load the page.

Flags: needinfo?(jteow)
Attachment #9495179 - Attachment description: Bug 1970997 - Add host validation check for persisted search terms - r?#urlbar-reviewers! → Bug 1970997 - Add origin validation check for persisted search terms - r?#urlbar-reviewers!
Pushed by jteow@mozilla.com: https://github.com/mozilla-firefox/firefox/commit/a34b558392eb https://hg.mozilla.org/integration/autoland/rev/c284d56dbb98 Add origin validation check for persisted search terms - r=urlbar-reviewers,mak
Status: NEW → RESOLVED
Closed: 9 months ago
Resolution: --- → FIXED
Target Milestone: --- → 141 Branch
QA Whiteboard: [search] [qa-triage-done-c141/b140] [qa-ver-needed-c141/b140]
Flags: qe-verify+
QA Contact: oardelean

I managed to reproduce the issue once on a 2025-06-06 Firefox Nightly build, using the string from the screenshot in Comment 0. Reproduced on macOS 15.
Verified as fixed on Firefox Nightly 142.0a1 and Firefox 141.0b1 on Windows 10, Ubuntu 22, macOS 15.

Status: RESOLVED → VERIFIED
QA Whiteboard: [search] [qa-triage-done-c141/b140] [qa-ver-needed-c141/b140] → [search] [qa-triage-done-c141/b140] [qa-ver-done-c141/b140]
Flags: qe-verify+

we should uplift this to ESR140, I think.

Flags: needinfo?(jteow)

Comment on attachment 9495179 [details]
Bug 1970997 - Add origin validation check for persisted search terms - r?#urlbar-reviewers!

ESR Uplift Approval Request

  • If this is not a sec:{high,crit} bug, please state case for ESR consideration: It could be confusing for users for the search terms to persist on non-search engine results pages.
  • User impact if declined: Intermittently, they might see the search terms persist in the address bar on a non search results page.
  • Fix Landed on Version: 141
  • Risk to taking this patch: Low
  • Why is the change risky/not risky? (and alternatives if risky): It's limited to the address bar feature that operates on search engine results pages. There are also automated tests.
Flags: needinfo?(jteow)
Attachment #9495179 - Flags: approval-mozilla-esr140?
Group: firefox-core-security
Blocks: 1974410

For clarity, "status-firefox140: wontfix" means we don't want to ship a 140.0.x point release for this. We do still want the uplift to make "status-firefox-esr140" fixed (tracking "141+" means "the ESR release in the 141 cycle", that is, 140.1)

Group: firefox-core-security → core-security-release
Attachment #9495179 - Flags: approval-mozilla-esr140? → approval-mozilla-esr140+
Whiteboard: [sng] → [sng][adv-main141+]
Whiteboard: [sng][adv-main141+] → [sng][adv-main141+][adv-ESR140.1+]
Attached file advisory.txt (obsolete) —

Verified as fixed on Firefox 140.1esr on Windows 10, Ubuntu 22, macOS 13.

Attached file advisory.txt
Attachment #9500522 - Attachment is obsolete: true
Alias: CVE-2025-8039
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: