Closed Bug 1979918 (CVE-2025-10535) Opened 1 year ago Closed 1 year ago

Swiping between Firefox and custom tab doesn't lock PBM

Categories

(Firefox for Android :: Privacy, defect, P2)

All
Android
defect

Tracking

()

RESOLVED FIXED
143 Branch
Tracking Status
firefox141 --- unaffected
firefox142 --- wontfix
firefox143 --- fixed

People

(Reporter: rebecatudor273, Assigned: mavduevskiy)

References

(Blocks 1 open bug)

Details

(4 keywords, Whiteboard: [fxdroid][group2][adv-main143+])

Attachments

(1 file, 1 obsolete file)

2.50 MB, video/mp4
Details

Steps to reproduce

  1. In Setting -> Private browsing -> enable "Use screen lock to hide tabs in private browsing.
  2. In Settings -> Set Firefox as the default browser to open the custom tabs in Firefox.
  3. Open a private browsing tab and visit some site in that tab, e.g. https://example.org .
  4. Switch to another app that can launch custom-tabs, e.g. Gmail, and tap some link to open a custom tab.
  5. Swipe back to Firefox.

Expected behavior

PBM is locked and authentication is required.

Actual behavior

PBM is unlocked

Attached video case2.mp4 —

What device are you using? I tested this on Firefox 141.0.1 (release downloaded from the Play Store) on my Pixel 8 using both PIN and facial recognition and I'm not able to reproduce this.

Never mind, I am able to reproduce this too.

Group: mobile-core-security

Bug 1971361 seems related. Kind of the opposite, so maybe fixing that broke this?

Keywords: privacy, sec-low
See Also: → 1971361

I observed this issue while working on Bug 1971361. The is can be reproduced before and after applying the patch from that ticket. So it's not related to it.

Assignee: nobody → anpopa
Attached file (secure) (obsolete) —

appstate.mode is updated by DefaultBrowsingModeManager during init phase; so that a custom tab is able to rewrite the mode set by the application. Managers calculate mode based on intent correctly, the missing peace was to update the appstate as well.

Attachment #9504431 - Attachment is obsolete: true

The issue was fixed with the patch added in Bug 1980721.

Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED

Are older releases affected or did this only affect 143?

Assignee: anpopa → mavduevskiy
Group: mobile-core-security → core-security-release
Depends on: 1980721
Flags: needinfo?(rebecatudor273)
Target Milestone: --- → 143 Branch

142 is affected too.

Flags: needinfo?(rebecatudor273)

The patch landed in nightly and beta is affected.
:mavduevskiy, is this bug important enough to require an uplift?

For more information, please visit BugBot documentation.

Flags: needinfo?(mavduevskiy)

Very late in the cycle to uplift a sec-low IMO. Feel free to nominate if you feel strongly otherwise, however.

Flags: needinfo?(mavduevskiy)
Whiteboard: [fxdroid][group2] → [fxdroid][group2][adv-main143+]
Alias: CVE-2025-10535
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: