New issue
Advanced search Search tips

Issue 591647 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Google Drive Security Issue

Reported by f.zielin...@gmail.com, Mar 3 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36

Steps to reproduce the problem:
1. Got 2 gmail accounts with password remember by google chrome.
2. Login to one of accounts. Logout and login to another one.
3. Open google drive for this second account.

What is the expected behavior?
I expect to open google drive for account that im login at.

What went wrong?
The problem is that I'm using 2 gmail accounts. Sometime if i logout from one of them and login to another and im gonna open google drive on this second one it opening content of first account. So my gmail relog succesfull but google drive not. Now im on f.zielinski.gliwice and i have access to another account drive content. I have it only for a while like 1-2 min but i think its a big security problem. In this situation both of accounts are mine but obviously this is not only possible situation. I got this 3rd time so i decide to report this issue. 
Regards
Filip ZieliƄski 

Did this work before? N/A 

Chrome version: 48.0.2564.116  Channel: n/a
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: Shockwave Flash 20.0 r0

It happends online sometime.
 
Labels: -Via-Wizard Needs-Feedback
Thanks for reporting,f.zielinski.gliwice!
So far, I cannot reproduce the problem you mentioned with the same version of chrome. In order to reproduce the problem you're experiencing. I need to ask you a couple of questions:
(1) have you logged-in chrome browser using either of your gmails? (You can check chrome://settings/ to find out) 
(2) How did you "open google drive" from the second account? from the apps icon at the top right corner or you open a new tab/window and type in the URL?

One more thing, if you do want to have a clear boundary between your two accounts, I would suggest you to use two separate profiles. Here is a link to a help article w.r.t this issue. Hope it can help.
https://support.google.com/chrome/answer/2364824?hl=en



Status: WontFix (was: Unconfirmed)
Wontfixing due to lack of response.
Project Member

Comment 3 by sheriffbot@chromium.org, Jun 17 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment