Security flaw: passwords on Firefox app for Android can be seen without entering phone pin/password.

Firefox for Android app, build 132.0.2. When opening the password tab, the prompt to enter your devices pin or password appears as it should. However, spamming the "canc… (read more)

Firefox for Android app, build 132.0.2.

When opening the password tab, the prompt to enter your devices pin or password appears as it should. However, spamming the "cancel" button on the prompt or the Android's back button (about 4 or 5 times) allows you to go to the password manager and view all usernames and passwords without reentering the device's pin/password.

To recreate: open the password tab, enter pin prompt opens, pressing cancel reopens the pin prompt, pressing cancel 4 or 5 times opens the password manager without verification.

Asked by talleyegrace לפני 5 ימים

no access to saved passwords on mobile

Hi. when i go into passwords, I am asked to unlock to view passwords, it says enter your device pin, I do this and it comes up again "unlock to view passwords" behind thi… (read more)

Hi. when i go into passwords, I am asked to unlock to view passwords, it says enter your device pin, I do this and it comes up again "unlock to view passwords" behind this message will be the first page of the password list, if you type in password again as requested it just locks up and you cant get off the page. I am using correct password it unlocks everything else. Please help all my passwords are unaccesable on the mobile, still ok on laptop, I have tried uninstalling firefox and re installing and rebooting mobile, no change. Thanks

Asked by Mick D לפני 6 ימים

תגובה אחרונה מאת Mick D לפני 6 ימים