Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
Trac
Trac
  • Project overview
    • Project overview
    • Details
    • Activity
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Operations
    • Operations
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value Stream
  • Wiki
    • Wiki
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Create a new issue
  • Issue Boards

GitLab is used only for code review, issue tracking and project management. Canonical locations for source code are still https://gitweb.torproject.org/ https://git.torproject.org/ and git-rw.torproject.org.

  • Legacy
  • TracTrac
  • Issues
  • #32733

Closed (moved)
Open
Opened Dec 12, 2019 by Trac@tracbot

"Find" feature leaks information between Tor Browser and regular Firefox on macOS 10.15.1

On my Macbook Pro (running Catalina 10.15.1) I use Firefox (currently v70) as my regular browser, and Tor Browser 9.0.2.

If I use the "find" feature in Tor Browser (i.e. Cmd-F) and look for some text in a page I am browsing privately via Tor, then using the same feature in normal Firefox is prefilled with the text I just searched for - this seems like a potential leak of private (meta-?)data

Steps to reproduce:

  • Install Firefox on a macOS 10.15.1 system
  • Install Tor Browser Bundle 9.0.2
  • Open Firefox and load "www.google.com"
  • Open Tor Browser and load "www.bing.com"
  • In Tor Browser, press Cmd-F and search for "private text"
  • Change application to Firefox and press Cmd-F
    • You will see that the "search text" field has been filled in with the text you just searched for in Tor Browser during an "anonymous" browsing session

Trac:
Username: mSUIcXNPzcq3idq

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
None
Due date
None
Reference: legacy/trac#32733