[tbb-bugs] #5288 [Applications/Tor Browser]: Clickjacking + popups subvert TBB url-bar isolation

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Oct 27 08:54:14 UTC 2016


#5288: Clickjacking + popups subvert TBB url-bar isolation
------------------------------------------------+--------------------------
 Reporter:  mikeperry                           |          Owner:  tbb-team
     Type:  defect                              |         Status:  new
 Priority:  Medium                              |      Milestone:
Component:  Applications/Tor Browser            |        Version:
 Severity:  Normal                              |     Resolution:
 Keywords:  tbb-linkability, tbb-firefox-patch  |  Actual Points:
Parent ID:                                      |         Points:
 Reviewer:                                      |        Sponsor:
------------------------------------------------+--------------------------
Changes (by bugzilla):

 * severity:   => Normal
 * milestone:  TorBrowserBundle 2.3.x-stable =>


Comment:

 Maybe, TBB should ask user whether he allows new tab/window to violate
 first-party isolation...

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5288#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list