Opened 14 months ago

Last modified 4 months ago

#27254 needs_information task

TBA: Investigate "Assist app" functionality

Reported by: towiw Owned by: tbb-team
Priority: Very High Milestone:
Component: Applications/Tor Browser Version:
Severity: Critical Keywords: tbb-mobile
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Why does fennec need to be an "Assist app"? Assist apps can take screenshots and read text in any app, and record audio. It is a very dangerous permission. I think this functionality should be removed from Tor Browser for Android.

Child Tickets

Change History (3)

comment:1 Changed 14 months ago by towiw

Fennec also becomes default Assist app if Google apps are not installed. You can find Assist app settings by searching 'Assist app' in settings.

comment:2 Changed 14 months ago by towiw3

When home button is long-pressed, Fennec is opened and a new tab is loaded. It appears to be using the Assist app permission only for opening Fennec and loading a new tab from anywhere. But still it is a dangerous permission. If Google apps are not installed and there is no other Assist app, TBA automatically becomes the Assist app.

comment:3 Changed 4 months ago by sysrqb

Status: newneeds_information

Oh, interesting. Thanks for reporting this! The documentation isn't descriptive, but this sounds like the missing piece in #30853. Also, there is mention of this action being deprecated in newer versions, but that the documentation doesn't say that.

We should investigate what this provides (overall) and test if a build without ACTION_ASSIST support allows unconditional screenshotting.

Note: See TracTickets for help on using tickets.