Closed Bug 2012012 (CVE-2026-2803) Opened 6 months ago Closed 6 months ago

“Require device sign-in to autofill and manage payment methods” checkbox's state can be changed even when device authentication is cancelled

Categories

(Firefox :: Settings UI, defect)

Firefox 147
Desktop
Windows 11
defect

Tracking

()

VERIFIED FIXED
149 Branch
Tracking Status
firefox-esr115 --- unaffected
firefox-esr140 --- unaffected
firefox147 --- wontfix
firefox148 + verified
firefox149 + verified

People

(Reporter: secure.blatantly440, Assigned: mtigley)

Details

(4 keywords, Whiteboard: [adv-main148+])

Attachments

(3 files)

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:147.0) Gecko/20100101 Firefox/147.0

Steps to reproduce:

  1. Open Firefox Settings
  2. Go to Privacy & Security → Payment methods
  3. Click the “Require device sign-in to autofill and manage payment methods” checkbox once
  4. Wait for the device authentication prompt (Windows) to appear
  5. While the authentication prompt is still open, return to Firefox and click the same checkbox a second time
  6. Cancel or close the device authentication prompt

Actual results:

After cancelling or closing the device authentication prompt, the checkbox changes state, even though authentication was not completed.

Expected results:

The checkbox state should only change after successful device authentication.
If authentication is cancelled or closed, the setting must remain unchanged.

OS: Unspecified → Windows 11
Hardware: Unspecified → Desktop
Attached video Video proof of the bug
Attachment #9539574 - Attachment is patch: true
Attachment #9539574 - Attachment is patch: false
Attachment #9539574 - Attachment mime type: text/plain → video/mp4
Component: Untriaged → Settings UI

Micah, can you take a look?

Flags: needinfo?(mtigley)

Does the changed checkbox state actually persist after a reload and/or lead to changed behaviour (i.e. do we actually stop/start prompting for Windows auth when filling payments) ?

Flags: needinfo?(rudydelsu)

(In reply to :Gijs (he/him) from comment #3)

Does the changed checkbox state actually persist after a reload and/or lead to changed behaviour (i.e. do we actually stop/start prompting for Windows auth when filling payments) ?

Yes.
The changed checkbox state does persist after reloading settings and after restarting Firefox.
After disabling the checkbox via this issue and restarting Firefox, Windows device authentication is no longer required when accessing or autofilling payment methods.
The behavior change is persistent and not limited to the current session.

Flags: needinfo?(rudydelsu)

I suspect the issue may be here. We are still setting the opposite value of the current state of the checkbox without authorization.

Assignee: nobody → mtigley
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Flags: needinfo?(mtigley)
Attached file (secure)
Group: firefox-core-security → core-security-release
Status: ASSIGNED → RESOLVED
Closed: 6 months ago
Resolution: --- → FIXED
Target Milestone: --- → 149 Branch

:mtigley, please add a beta uplift request when you have a moment

Flags: needinfo?(mtigley)
Attachment #9540417 - Flags: approval-mozilla-beta?

firefox-beta Uplift Approval Request

  • User impact if declined: “Require device sign-in to autofill and manage payment methods” checkbox's state can be changed even when device authentication is cancelled

  • Code covered by automated testing: no

  • Fix verified in Nightly: no

  • Needs manual QE test: yes

  • Steps to reproduce for manual QE testing: Steps to reproduce:

    1. Open Firefox Settings
    2. Go to Privacy & Security → Payment methods
    3. Click the “Require device sign-in to autofill and manage payment methods” checkbox once
    4. Wait for the device authentication prompt (Windows) to appear
    5. While the authentication prompt is still open, return to Firefox and click the same checkbox a second time
      Cancel or close the device authentication prompt

Actual results:
After cancelling or closing the device authentication prompt, the checkbox changes state, even though authentication was not completed.

Expected results:
The checkbox state should only change after successful device authentication.
If authentication is cancelled or closed, the setting must remain unchanged.

  • Risk associated with taking this patch: low
  • Explanation of risk level: Small change in code
  • String changes made/needed: no
  • Is Android affected?: no
Flags: qe-verify+

Hi Alin, would you be able to verify the fix on the latest Nightly? Thank you!

Flags: needinfo?(ailea)
Attachment #9540417 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
QA Whiteboard: [uplift][qa-ver-needed-c149/b§48]

Reproduced the issue in release 147.0.1
Verified - Fixed in Nightly 149.0a1 (build id: 20260127212501). The checkbox state only change after successful device authentication.
Will verify it in Beta 8 as well, as soon as it's ready.

Has STR: --- → yes
Flags: needinfo?(ailea)
QA Contact: ailea

Verified - Fixed in Beta 148.0b8 (build id: 20260128090352).

Status: RESOLVED → VERIFIED
QA Whiteboard: [uplift][qa-ver-needed-c149/b§48] → [uplift][qa-ver-done-c149/b§48]
Flags: qe-verify+
QA Whiteboard: [uplift][qa-ver-done-c149/b§48] → [uplift][qa-ver-done-c149/b148]
Whiteboard: [adv-main148+]
Alias: CVE-2026-2803
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: