Low firefox Logic Error 🔧 Commit mapped

Overview

Low
Severity
CVSS
No
Exploited ITW
Fixed
Fix Status
Impactlow
DescriptionClickjacking issue in the DOM: Events component
ComponentDOM
Bug ClassLogic Error
Tracker2060153
Fix commite423fd5de85f (firefox) +20/-6
CISA KEVNot listed
CreditedLong Nguyen
Disclosed2026-09-01

Changed Functions

FunctionChangeNotes
mShowingTooltip
dom/ipc/BrowserParent.cpp
modified

Files Changed

  • dom/ipc/BrowserParent.cpp
  • dom/ipc/BrowserParent.h
diff --git a/dom/ipc/BrowserParent.cpp b/dom/ipc/BrowserParent.cpp
index 7a10bef57a8..e6946d3f8a3 100644
--- a/dom/ipc/BrowserParent.cpp
+++ b/dom/ipc/BrowserParent.cpp
@@ -324,6 +324,7 @@ BrowserParent::BrowserParent(ContentParent* aManager, const TabId& aTabId,
       mIsReadyToHandleInputEvents(false),
       mIsMouseEnterIntoWidgetEventSuppressed(false),
       mLockedNativePointer(false),
+      mWaitingForNativeMouseMoveAfterUnlock(false),
       mShowingTooltip(false) {
   MOZ_ASSERT(aManager);
 
@@ -1995,8 +1996,14 @@ mozilla::ipc::IPCResult BrowserParent::RecvSynthesizeNativeMouseEvent(
 
 mozilla::ipc::IPCResult BrowserParent::RecvSynthesizeNativeMouseMove(
     const LayoutDeviceIntPoint& aPoint, const Maybe<uint64_t>& aCallbackId) {
-  // This is used by pointer lock API.  So, even if it's not in the automation
-  // mode, we need to accept the request.
+  NS_ENSURE_TRUE(
+      xpc::IsInAutomation()
+          // This is used by pointer lock API.  So, even if it's not
+          // in the automation mode, we need to accept the request.
+          || (mLockedNativePointer || mWaitingForNativeMouseMoveAfterUnlock),
+      IPC_FAIL(this, "Unexpected event"));
+
+  mWaitingForNativeMouseMoveAfterUnlock = false;
   nsCOMPtr<nsISynthesizedEventCallback> callback =
       SynthesizedEventCallback::MaybeCreate(this, aCallbackId);
   if (nsCOMPtr<nsIWidget> widget = GetWidget()) {
@@ -2111,8 +2118,9 @@ mozilla::ipc::IPCResult BrowserParent::RecvLockNativePointer(
     const nsIWidget::NativePointerLockMode& aNativePointerLockMode) {
   // XXX(edgar): LockNativePointer IPC message can be removed if pointer lock
   // is handled mainly from parent process.
-  MOZ_ASSERT(
-      !StaticPrefs::dom_pointer_lock_reset_to_center_from_parent_enabled());
+  NS_ENSURE_TRUE(
+      !StaticPrefs::dom_pointer_lock_reset_to_center_from_parent_enabled(),
+      IPC_FAIL(this, "Unexpected request"));
 
   if (nsCOMPtr<nsIWidget> widget = GetWidget()) {
     mLockedNativePointer = true;
@@ -2128,14 +2136,16 @@ void BrowserParent::UnlockNativePointer() {
   if (nsCOMPtr<nsIWidget> widget = GetWidget()) {
     widget->UnlockNativePointer();
     mLockedNativePointer = false;
+    mWaitingForNativeMouseMoveAfterUnlock = true;
   }
 }
 
 mozilla::ipc::IPCResult BrowserParent::RecvUnlockNativePointer() {
   // XXX(edgar): LockNativePointer IPC message can be removed if pointer lock
   // is handled mainly from parent process.
-  MOZ_ASSERT(
-      !StaticPrefs::dom_pointer_lock_reset_to_center_from_parent_enabled());
+  NS_ENSURE_TRUE(
+      !StaticPrefs::dom_pointer_lock_reset_to_center_from_parent_enabled(),
+      IPC_FAIL(this, "Unexpected request"));
   UnlockNativePointer();
   return IPC_OK();
 }
diff --git a/dom/ipc/BrowserParent.h b/dom/ipc/BrowserParent.h
index f8bf09f3f23..f2537eccb92 100644
--- a/dom/ipc/BrowserParent.h
+++ b/dom/ipc/BrowserParent.h
@@ -1023,6 +1023,10 @@ class BrowserParent final : public PBrowserParent,
   // UnlockNativePointer has been called.
   bool mLockedNativePointer : 1;
 
+  // True after mLockedNativePointer is changed to `false` and reset to false
+  // once we receive a native mouse move request.
+  bool mWaitingForNativeMouseMoveAfterUnlock : 1;
+
   // True between ShowTooltip and HideTooltip messages.
   bool mShowingTooltip : 1;
 };
Loading diff…