New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 592257 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: ----
Type: Bug



Sign in to add a comment

Security: Google chrome show password without any auth on Linux

Reported by djki...@gmail.com, Mar 6 2016

Issue description

I am using Ubuntu 15.10 and my google chrome Version is 48.0.2564.116 (64-bit). I observed google chrome show mange password without authentication.
Few versions before google fixed this vul but in this version i faced this.
In the attachment print screen are attached.
If you need anything more then update me.

Thanks
 
google1.png
84.2 KB View Download
google-2.png
78.3 KB View Download
Cc: jialiul@chromium.org
Components: UI>Browser>Passwords
Labels: Security_Severity-High Security_Impact-Stable OS-Linux
Owner: vasi...@chromium.org
Status: Untriaged (was: Unconfirmed)
Thanks for reporting, djkiani. 
I tested "manage password" function on both mac and linux, it seems this problem only happens on Linux. 
Adding more labels to this bug to help triage. 

+vasilii@, you know better than me in this area. Could you take a look at this bug?
Status: Available (was: Untriaged)
Owner: vabr@chromium.org
The reauth has never been implemented on Linux due to lower priority than other OS. Reassigning to vabr@ to triage.

Comment 4 by wfh@chromium.org, Mar 7 2016

Labels: -Type-Bug-Security -Restrict-View-SecurityTeam -Security_Impact-Stable -Security_Severity-High Type-Feature
Summary: Security: Google chrome show password without any auth on Linux (was: Security: Google chrome show password without any auth)

Comment 5 by djki...@gmail.com, Mar 7 2016

Hi,

We observe this issue chromium also on linux. Have you check it?

Thanks
Hi djkiani, 
Chromium and chrome share basic code basis. I'm waiting for vabr@ to triage this bug. Most likely, this issue is work as intended according to #3. 

Comment 7 by djki...@gmail.com, Mar 8 2016

@Jialiul: I have tested this in windows also but still same problem there? I can access all stored password from browser UI password manager. 
I have tested this on window 7-sp1 with latest chrome browser.

Thanks
vabr@, could you chime in?

Comment 9 by vabr@chromium.org, Mar 8 2016

Labels: -Type-Feature Needs-Feedback Type-Bug
Owner: ----
Status: Unconfirmed (was: Available)
This is a known issue on Linux and Chrome OS.

On windows there should be reauthentication, as long as the OS account also has a password. djkiani, do you use a password to log into your Windows machine?

Comment 10 by djki...@gmail.com, Mar 8 2016

In window i am not using password for os-login, without this i can access all stored password. 

When you make this change for linux? i remember few months ago i tested this that time it's work fine on linux. 

Comment 11 by vabr@chromium.org, Mar 9 2016

Labels: -Needs-Feedback
Status: WontFix (was: Unconfirmed)
Thanks for your response.
If you do not use password for OS login on Windows, there will not be a password to enter before viewing Chrome's passwords either, that is working as intended, because the only password Chrome on any platform uses to guard password viewing is the OS password.

Viewing passwords has never been guarded by a password on Linux.

Comment 12 by djki...@gmail.com, Mar 10 2016

@Vabr: Thanks for your detail answer. You said it's not a issue or already known issue about chrome on Windows and Linux both?
Because i am going to write an article about it.

Comment 13 by vabr@chromium.org, Mar 10 2016

This is a known issue for Linux, and working as intended for Windows (as long as using a non-empty Windows OS password results in the reauthentication prompt appearing before viewing passwords).

Comment 14 by djki...@gmail.com, Mar 12 2016

@Vabr: I am successfully view password on windows machine. I am using window 7 32bit with latest chrome. Kindly check the screenshot of screen. 

win-1.png
130 KB View Download
win2.png
155 KB View Download
win3.png
156 KB View Download

Comment 15 by vabr@chromium.org, Mar 14 2016

@djklani: What exactly is your question?

Comment 16 by djki...@gmail.com, Mar 14 2016

@Vabr: I don't have any question. I found a security issue in chrome and i reported. 
May be you didn't catch my point. 
Cc: timwillis@chromium.org
Hi djkiani@,
To summarize previous replies. 
(1) On Linux, showing passwords without re-auth is a known issue 
(2) On windows, showing passwords without re-auth only happens if OS account does not have a password. However, if you have password for your OS account, it will prompt you to re-auth.
So what you have experienced is work-as-intended (i.e. works as the system is designed) based on comment #10.
Given the two points above, we marked this report as "Won'tFix". 
+ timwills@ to the thread, in case you want to know more about the Vulnerability reward program. 

Comment 18 by vabr@chromium.org, Mar 15 2016

jialiui@ summarised this well.
djkiani@ did not find a security issue, this all is working as intended.

Comment 19 by djki...@gmail.com, Mar 19 2016

@vabr: Thanks for your guide. Everything going as expected. No new issue observed in this.
Kindly close this thread.

Thanks

Sign in to add a comment