Torbutton should block remote protocol handler enumeration. We currently wrap the external protocol handler launching components, and install custom protocol handlers to handle tor:// urls. We should see if we can perform any tricks in these components to defeat http://pseudo-flaw.net/tor/torbutton/scan-protocol-handlers.html.
Designs
Child items 0
Show closed items
No child items are currently assigned. Use child items to break down this issue into smaller parts.
Linked items 0
Link issues together to show that they're related.
Learn more.
Looks good. Cherry-picked to tor-browser-60.2.1esr-8.5-1 (commits 8ac83f77, 0a5a1991, and d098b183) and marked for possible backport. This should be available starting with Tor Browser 8.5a4.