Open
Bug 318881
Opened 20 years ago
Updated 3 years ago
when moving across the tabs with ctrl+tab the focus will remain on the last browsed page
Categories
(Firefox :: Security, defect)
Tracking
()
NEW
People
(Reporter: urifrid, Unassigned)
References
Details
(Keywords: sec-other, Whiteboard: [sg:nse])
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8) Gecko/20051111 Firefox/1.5
Build Identifier: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8) Gecko/20051111 Firefox/1.5
when open more than one site using the tabbed interface and browsing thru them with ctrl+tab (the shortcut), the focus will remain on the last site with user interaction (a click on a link, or a search, etc). this doesnt accur when moving to the next (or previous) tab using the mouse. even when you close a tab (using ctrl+w), that focus will not change to the actual showing tab, it will remain on the non existing site. i've seen this happen since release 1.0
Reproducible: Always
Steps to Reproduce:
1.open a site, press ctrl+t for a new tab and open another site
2.press any links on the last site opened or search anything, press ctrl-tab to move to the other tab
3.try scrolling down, the site won't scroll, but when you return to the site that you previously worked with you will find that it scrolled down
Actual Results:
only the site last interacted with will recieve the focus
Expected Results:
when pressing ctrl+tab the focus should move to the current tab
this happens even when closing a tab, the focus will reamin on the last interacted site, even when it doesnt exist anymore.
Related to bug 286362?
Comment 3•20 years ago
|
||
But bug 286362 is closed with a statement that it is fixed in 1.0.7, however I still see the behavior described in this bug and the original report was for 1.5.
My Version is: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.12) Gecko/20050915 Firefox/1.0.7
It appears to be fixed on
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) Gecko/2006120502 Iceweasel/2.0.0.1 (Debian-2.0.0.1+dfsg-2)
however in some other circumstances focus stays in the previous tab, I still have to test more to accurately describe the circumstances, because this is annoying - I use keyboard only.
I'm growing old waiting for this bug to be fixed. I can't figure out what triggers it, but focus often remains on the wrong tab after I switch.
I use keyboard only in all apps except firefox. Due to tendonitis, using the mouse is difficult and painful for me. Please fix.
Comment 7•17 years ago
|
||
Also seen on Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.0.11) Gecko/2009060308 Ubuntu/9.04 (jaunty) Firefox/3.0.11. I was using Site A in my fourth and last tab (counting from the left), then switched tabs to Site B on my first tab from the left using Ctrl+Tab. I proceeded to type in my password for Site B but soon discovered that the focus remained on Site A. When I switched back to Site A, my password had been entered into a textbox there.
Needless to say, this is a critical security bug, as it can disclose private information to random sites. I don't know of any way for Site A to trigger the problem intentionally, but it happens often enough by itself to be considered a grave problem.
Status: UNCONFIRMED → NEW
Component: Tabbed Browser → Security
Ever confirmed: true
QA Contact: tabbed.browser → firefox
Version: unspecified → 3.0 Branch
Updated•17 years ago
|
OS: Linux → All
Comment 8•17 years ago
|
||
(In reply to comment #7)
> Also seen on Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.0.11)
> Gecko/2009060308 Ubuntu/9.04 (jaunty) Firefox/3.0.11.
I cannot reproduce this using Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.0.11) Gecko/2009060214 Firefox/3.0.11. I tried the same steps outlined in comment 7 and focus stays with the current tab in all the variations I tried. Do you have any extensions installed that could be causing this behavior? You can test this by starting Firefox in Safe Mode which disables all extensions by running "firefox -safe-mode".
> Needless to say, this is a critical security bug, as it can disclose private
> information to random sites.
Actually, it is not a critical security bug. Under our rating system critical security bugs generally require remote code execution:
https://wiki.mozilla.org/Security_Severity_Ratings
Additionally, this isn't a bug which can be leveraged specifically by attackers so hiding it will not provide any security benefits to users and will in fact prevent the majority of community members from seeing the contents of the bug, thus delaying a fix.
Comment 9•17 years ago
|
||
Sorry, I forgot to check the wiki for severity terminology. Also thanks for taking a look at this.
The bug is difficult to reproduce because it doesn't happen every time (or maybe it happens every time, but we haven't fully described all the steps). But it happens often enough that I have a "Where's the focus" moment at least twice a day when using Firefox. The new revelation for me is that the focus isn't just in a black hole, like I previously believed, but instead the focus is on a background tab.
I think your statement that this bug cannot be leveraged specifically by attackers is unsupported by the available evidence. Since we don't know how this bug is triggered, we can't rule out the possibility that adversaries can specifically trigger it. If someone can figure out a way to reliably or even probably trigger this, then they can open your bank's site or your webmail in a new tab and see what happens.
Comment 10•17 years ago
|
||
I'm running the latest firefox 3.0.11 on ubuntu and can confirm it's still a problem for me. It happens even with a virgin install and no extensions. And it happens often enough that I don't even bother trying to use the scroll keys. I scroll by dragging the scroll bar with the mouse. I do not have a way to reliably reproduce it but I doubt I could use firefox for more than about ten minutes without triggering this bug.
Updated•17 years ago
|
Whiteboard: [sg:investigate]
Comment 11•16 years ago
|
||
Still a problem under
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)
I can't really reproduce it, but if it occurs, it occurs on all currently open tabs. I often see it when I use middle-click to open a tab in the background, then [ctrl]+[tab] to it and then try to scroll down via [space] which does not work.
Comment 12•16 years ago
|
||
It does seem to frequently happen when I middle-click then use ctl-tab to switch tabs. Still happens with 3.5.5. I did find a workaround, which is to click in the tab that I want to get the focus.
This bug should be marked "won't fix" along with all the other focus bugs. I'm sure no one is going to fix it in 3.x, and 4.x will probably have an entirely different set of focus bugs.
Updated•16 years ago
|
Whiteboard: [sg:investigate] → [sg:nse]
Comment 13•16 years ago
|
||
Bug is still there in Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.1.8) Gecko/20100214 Ubuntu/9.10 (karmic) Firefox/3.5.8.
Comment 14•15 years ago
|
||
Can't recall this happen in recent 3.6. Anyone still seeing this?
Comment 15•14 years ago
|
||
I'm not seeing this.
The closest neighbour to this is the legendary bug 78414.
Comment 16•14 years ago
|
||
I can sort-of repro on Fedora, Firefox 10.0.1.
After playing 8bitmmo (8bitmmo.net) for a while and switching between the tab with the game and a tab with a qwebirc instance in it, sometimes when I try to move (wasd) in the tab with the game (before I click to focus the java widget) it will send the text to the irc input field instead.
When it does happen, you can easily reproduce by switching back and forth between the tabs and sending input. But after refreshing the tab with the game, it goes away again.
Updated•3 years ago
|
Severity: normal → S3
You need to log in
before you can comment on or make changes to this bug.
Description
•