Mozilla サポートの検索

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

詳しく学ぶ

Security flaw: passwords on Firefox app for Android can be seen without entering phone pin/password.

  • 返信なし
  • 2 人がこの問題に困っています
more options

Firefox for Android app, build 132.0.2.

When opening the password tab, the prompt to enter your devices pin or password appears as it should. However, spamming the "cancel" button on the prompt or the Android's back button (about 4 or 5 times) allows you to go to the password manager and view all usernames and passwords without reentering the device's pin/password.

To recreate: open the password tab, enter pin prompt opens, pressing cancel reopens the pin prompt, pressing cancel 4 or 5 times opens the password manager without verification.

Firefox for Android app, build 132.0.2. When opening the password tab, the prompt to enter your devices pin or password appears as it should. However, spamming the "cancel" button on the prompt or the Android's back button (about 4 or 5 times) allows you to go to the password manager and view all usernames and passwords without reentering the device's pin/password. To recreate: open the password tab, enter pin prompt opens, pressing cancel reopens the pin prompt, pressing cancel 4 or 5 times opens the password manager without verification.

投稿に返信するには あなたのアカウントにログイン する必要があります。まだアカウントをお持ちでなければ、新しい質問を開始 してください。