Not sure if they are as easily exploitable in Tor Browser as they are in Firefox but we should be better safe here than sorry and backport the pref changes coming with bug 1552627 and 1549833.
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Child items 0
Show closed items
No child items are currently assigned. Use child items to break down this issue into smaller parts.
Linked items 0
Link issues together to show that they're related.
Learn more.
bug_30849 (https://gitweb.torproject.org/user/gk/tor-browser.git/log/?h=bug_30849) does contain the last two changes as they are simple preference settings. I am not sure about the first one as it is more a fix to make social engineering harder and it seems to require some work to get it properly applied to esr60...
Thanks! Cherry-picked to tor-browser-60.7.0esr-9.0-1 (commit 35560e850f9dbf29e18895b3e55ad9b4e684cd24 and 0be8d76933ec1e36553f1bfaffb261169757fa77) and tor-browser-60.7.0esr-8.5-1 (commit e0c4aa5835df2a0ea4c2555872fc467649e2cc49 and cb68eb598242fd211bf032e704069ea453f57c05).
Trac: Resolution: N/Ato fixed Status: merge_ready to closed