Closed Bug 1982308 Opened 1 year ago Closed 1 year ago

Copied text might not match displayed text

Categories

(Core :: DOM: Copy & Paste and Drag & Drop, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 504748

People

(Reporter: michel, Unassigned)

Details

Attachments

(1 file)

  1. Go to a malicious website that displays a command and has a copy button (please use the attached example)
  2. The website shows a useful harmless command and a handy button to copy it
  3. The website does:
const textarea = document.createElement('textarea');
textarea.value = "Very evil command";
textarea.setAttribute('readonly', '');
document.body.appendChild(textarea);
textarea.select();
document.execCommand('copy');
document.body.removeChild(textarea);

that copies a different text than the displayed one
4. The user pastes the command in the terminal and out of habit presses enter before realizing that the copied command does not match the command that he saw before.

I think that Firefox should ensure that textarea is displayed for a minimum of X seconds or on page load before allowing doing copy on it

Attached file Example —
Group: core-security
Status: NEW → RESOLVED
Closed: 1 year ago
Duplicate of bug: 504748
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: