[Atlas Browser]Bypass the full-screen notification security layer by displaying a permission dialog to open an external app

Disclosed by
Moch_Azril
  • Engagement OpenAI
  • Disclosed date about 4 hours ago
  • Points 5
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by Moch_Azril

A UI-confusion vulnerability allows a webpage to trigger a browser fullscreen request and immediately redirect to an external application using a tel: URI. The resulting system-level external-application prompt can overlap or obscure the browser's fullscreen notification.

This creates a trusted-UI spoofing condition where users may be unable to clearly distinguish which action they are authorizing. When combined with attacker-controlled fullscreen content or another security-sensitive browser prompt such as WebAuthn, the issue could facilitate clickjacking, permission spoofing, and phishing attacks.

Activity