Open Bug 1486598 Opened 6 years ago Updated 2 years ago

Web Authn Origin Forgery through IPC

Categories

(Core :: DOM: Web Authentication, enhancement, P3)

enhancement

Tracking

()

Fission Milestone Future

People

(Reporter: tjr, Unassigned)

References

(Depends on 1 open bug, Blocks 1 open bug)

Details

(Whiteboard: [domsecurity-backlog2] [webauthn])

While performing a cursory review of Web Authn IPC, it appears that the origin for a Web Authn request comes from the child (in Origin of WebAuthnGetAssertionInfo in https://searchfox.org/mozilla-central/source/dom/webauthn/PWebAuthnTransaction.ipdl ). In the future, we should validate that the origin provided matches the origin of the content process it comes from.
Priority: -- → P3
Whiteboard: [domsecurity-backlog2]
Whiteboard: [domsecurity-backlog2] → [domsecurity-backlog2] [webauthn]
Depends on: fission-ipc-map
Component: DOM: Security → DOM: Web Authentication

This bug is not a Fission MVP blocker.

Fission Milestone: --- → Future
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.