Torbutton should block remote protocol handler enumeration. We currently wrap the external protocol handler launching components, and install custom protocol handlers to handle tor:// urls. We should see if we can perform any tricks in these components to defeat http://pseudo-flaw.net/tor/torbutton/scan-protocol-handlers.html.
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Child items 0
Show closed items
No child items are currently assigned. Use child items to break down this issue into smaller parts.
Linked items 0
Link issues together to show that they're related.
Learn more.
Looks good. Cherry-picked to tor-browser-60.2.1esr-8.5-1 (commits 8ac83f77ae144a3063c57099c250a340fd4bf0ac, 0a5a1991dec543177e78283f27407e2a6d4892d8, and d098b183150a7feb83f159ad731fc42537252863) and marked for possible backport. This should be available starting with Tor Browser 8.5a4.
Backported to tor-browser-60.3.0esr-8.0-1 (commits d0571f8b98a5a98e59974b4868c0fcccaea17748, 818556471232f9a9a4caebc3c37cae387a43bbd7, and bec054919416df19648702f2af0b9a0be1c384b8)