[tbb-bugs] #30657 [Applications/Tor Browser]: Tor Browser locale is leaked via title of link tag on non-html page (was: Tor Browser locale is leaked via title of link tag on 404 error page)

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue May 28 09:24:45 UTC 2019


#30657: Tor Browser locale is leaked via title of link tag on non-html page
---------------------------------------+--------------------------
 Reporter:  gk                         |          Owner:  tbb-team
     Type:  defect                     |         Status:  new
 Priority:  High                       |      Milestone:
Component:  Applications/Tor Browser   |        Version:
 Severity:  Normal                     |     Resolution:
 Keywords:  tbb-fingerprinting-locale  |  Actual Points:
Parent ID:                             |         Points:
 Reviewer:                             |        Sponsor:
---------------------------------------+--------------------------
Description changed by gk:

Old description:

> ryotak reported via our HackerOne bug bounty program that the Tor Browser
> locale is leaked via the title of link tag on 404 error page.
>
> For a test ryotak came up with see:
> https://people.torproject.org/~gk/tests/tor_plaintext_locale_leak.html.

New description:

 ryotak reported via our HackerOne bug bounty program that the Tor Browser
 locale is leaked via the title of the link tag on any non-html page.

 For a test ryotak came up with see:
 https://people.torproject.org/~gk/tests/tor_plaintext_locale_leak.html.

--

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/30657#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list