搜尋 Mozilla 技術支援網站

防止技術支援詐騙。我們絕對不會要求您撥打電話或發送簡訊,或是提供個人資訊。請用「回報濫用」功能回報可疑的行為。

了解更多

Security flaw: passwords on Firefox app for Android can be seen without entering phone pin/password.

  • 無回覆
  • 2 有這個問題
more options

Firefox for Android app, build 132.0.2.

When opening the password tab, the prompt to enter your devices pin or password appears as it should. However, spamming the "cancel" button on the prompt or the Android's back button (about 4 or 5 times) allows you to go to the password manager and view all usernames and passwords without reentering the device's pin/password.

To recreate: open the password tab, enter pin prompt opens, pressing cancel reopens the pin prompt, pressing cancel 4 or 5 times opens the password manager without verification.

Firefox for Android app, build 132.0.2. When opening the password tab, the prompt to enter your devices pin or password appears as it should. However, spamming the "cancel" button on the prompt or the Android's back button (about 4 or 5 times) allows you to go to the password manager and view all usernames and passwords without reentering the device's pin/password. To recreate: open the password tab, enter pin prompt opens, pressing cancel reopens the pin prompt, pressing cancel 4 or 5 times opens the password manager without verification.

如果您還沒有帳號,您必須先登入帳號 來回覆文章。還沒有帳號的話,只能發問新問題