Open Bug 2014164 Opened 8 days ago Updated 7 days ago

Suspicious cross-site cookies access from sqlite.org on news.ycombinator.com

Categories

(Core :: Privacy: Anti-Tracking, defect)

Firefox 147
defect

Tracking

()

UNCONFIRMED

People

(Reporter: awalgarg, Unassigned)

References

Details

Attachments

(1 file)

User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:147.0) Gecko/20100101 Firefox/147.0

Steps to reproduce:

  1. Visit news.ycombinator.com.
  2. Notice a new "cog" icon in the url bar.
  3. Click on it.
  4. It shows that sqlite.org is allowed to access to cross-site cookies.

This does not happen on the machine of other users in IRC.

As far as I understand, for this to happen, sqlite.org would have had to send a request to news.ycombinator.com in some manner at least.

Now I'm assuming that sqlite.org would not have done that. I'm also assuming that sqlite.org was not compromised (I don't use any machine which could have faced any TLS compromise). In fact I rarely visit sqlite.org.

I'm not claiming that this is necessarily an issue with Firefox, but I find it odd and suspicious enough that I figured it'd be better to report it than not.

Actual results:

  1. It shows that sqlite.org is allowed to access to cross-site cookies.

Expected results:

  1. It should not show that or anything like that.

This is most likely triggered by one of our storage access heuristics which are used to unbreak common flows that rely on unpartitioned cookie access.
This is not a security issue, more likely an overly eager storage access heuristic. The site boundary for cookies is intact, i.e. sqlite.org isn't suddently allowed to access news.ycombinator.com's cookies.

Group: firefox-core-security
Component: Untriaged → Privacy: Anti-Tracking
Product: Firefox → Core

See https://developer.mozilla.org/en-US/docs/Web/Privacy/Guides/State_Partitioning#storage_access_heuristics for more details. I haven't confirmed whether the heuristics are behaving correctly in this case.

See Also: → 2012692
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: