Security: Google chrome show password without any auth on Linux
Reported by
djki...@gmail.com,
Mar 6 2016
|
|||||||
Issue descriptionI am using Ubuntu 15.10 and my google chrome Version is 48.0.2564.116 (64-bit). I observed google chrome show mange password without authentication. Few versions before google fixed this vul but in this version i faced this. In the attachment print screen are attached. If you need anything more then update me. Thanks
,
Mar 7 2016
,
Mar 7 2016
The reauth has never been implemented on Linux due to lower priority than other OS. Reassigning to vabr@ to triage.
,
Mar 7 2016
,
Mar 7 2016
Hi, We observe this issue chromium also on linux. Have you check it? Thanks
,
Mar 7 2016
Hi djkiani, Chromium and chrome share basic code basis. I'm waiting for vabr@ to triage this bug. Most likely, this issue is work as intended according to #3.
,
Mar 8 2016
@Jialiul: I have tested this in windows also but still same problem there? I can access all stored password from browser UI password manager. I have tested this on window 7-sp1 with latest chrome browser. Thanks
,
Mar 8 2016
vabr@, could you chime in?
,
Mar 8 2016
This is a known issue on Linux and Chrome OS. On windows there should be reauthentication, as long as the OS account also has a password. djkiani, do you use a password to log into your Windows machine?
,
Mar 8 2016
In window i am not using password for os-login, without this i can access all stored password. When you make this change for linux? i remember few months ago i tested this that time it's work fine on linux.
,
Mar 9 2016
Thanks for your response. If you do not use password for OS login on Windows, there will not be a password to enter before viewing Chrome's passwords either, that is working as intended, because the only password Chrome on any platform uses to guard password viewing is the OS password. Viewing passwords has never been guarded by a password on Linux.
,
Mar 10 2016
@Vabr: Thanks for your detail answer. You said it's not a issue or already known issue about chrome on Windows and Linux both? Because i am going to write an article about it.
,
Mar 10 2016
This is a known issue for Linux, and working as intended for Windows (as long as using a non-empty Windows OS password results in the reauthentication prompt appearing before viewing passwords).
,
Mar 12 2016
@Vabr: I am successfully view password on windows machine. I am using window 7 32bit with latest chrome. Kindly check the screenshot of screen.
,
Mar 14 2016
@djklani: What exactly is your question?
,
Mar 14 2016
@Vabr: I don't have any question. I found a security issue in chrome and i reported. May be you didn't catch my point.
,
Mar 14 2016
Hi djkiani@, To summarize previous replies. (1) On Linux, showing passwords without re-auth is a known issue (2) On windows, showing passwords without re-auth only happens if OS account does not have a password. However, if you have password for your OS account, it will prompt you to re-auth. So what you have experienced is work-as-intended (i.e. works as the system is designed) based on comment #10. Given the two points above, we marked this report as "Won'tFix". + timwills@ to the thread, in case you want to know more about the Vulnerability reward program.
,
Mar 15 2016
jialiui@ summarised this well. djkiani@ did not find a security issue, this all is working as intended.
,
Mar 19 2016
@vabr: Thanks for your guide. Everything going as expected. No new issue observed in this. Kindly close this thread. Thanks |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by jialiul@chromium.org
, Mar 6 2016Components: UI>Browser>Passwords
Labels: Security_Severity-High Security_Impact-Stable OS-Linux
Owner: vasi...@chromium.org
Status: Untriaged (was: Unconfirmed)