Closed
Bug 1982308
Opened 1 year ago
Closed 1 year ago
Copied text might not match displayed text
Categories
(Core :: DOM: Copy & Paste and Drag & Drop, defect)
Core
DOM: Copy & Paste and Drag & Drop
Tracking
()
RESOLVED
DUPLICATE
of bug 504748
People
(Reporter: michel, Unassigned)
Details
Attachments
(1 file)
|
784 bytes,
text/html
|
Details |
- Go to a malicious website that displays a command and has a copy button (please use the attached example)
- The website shows a useful harmless command and a handy button to copy it
- The website does:
const textarea = document.createElement('textarea');
textarea.value = "Very evil command";
textarea.setAttribute('readonly', '');
document.body.appendChild(textarea);
textarea.select();
document.execCommand('copy');
document.body.removeChild(textarea);
that copies a different text than the displayed one
4. The user pastes the command in the terminal and out of habit presses enter before realizing that the copied command does not match the command that he saw before.
I think that Firefox should ensure that textarea is displayed for a minimum of X seconds or on page load before allowing doing copy on it
| Reporter | ||
Comment 1•1 year ago
|
||
Updated•1 year ago
|
Group: core-security
Status: NEW → RESOLVED
Closed: 1 year ago
Duplicate of bug: 504748
Resolution: --- → DUPLICATE
You need to log in
before you can comment on or make changes to this bug.
Description
•