[tbb-bugs] #29647 [Applications/Tor Browser]: Browser freezing due to NoScript XSS protection

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Mar 4 11:53:31 UTC 2019


#29647: Browser freezing due to NoScript XSS protection
--------------------------+------------------------------------------
 Reporter:  atac          |          Owner:  tbb-team
     Type:  defect        |         Status:  new
 Priority:  Medium        |      Component:  Applications/Tor Browser
  Version:                |       Severity:  Normal
 Keywords:  xss noscript  |  Actual Points:
Parent ID:                |         Points:
 Reviewer:                |        Sponsor:
--------------------------+------------------------------------------
 I can reproduce 100% on https://www.tripadvisor.com/Tourism-g60763
 -New_York_City_New_York-Vacations.html, on Linux 64 (Ubuntu 18.04). Before
 page being completely loaded, the whole browser freezes for a while (at
 least 60 seconds), then some XSS popups appear.

 Unticking `NoScript Preferences` -> `Advanced` -> `Sanitize cross-site
 suspicious requests` fixes it, so I assume this is being caused by
 NoScript XSS protection. I was surprised that the whole browser is
 freezing, but it must be that the NoScript WebExtension runs in the main
 process.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/29647>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list