New issue
Advanced search Search tips

Issue 594401 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: "Bring me water" password reveal

Reported by stefanin...@gmail.com, Mar 13 2016

Issue description

VULNERABILITY DETAILS

I have found a way to expose user password in Chrome on Windows and Mac operating systems. It is very simple. First you need to say to your friend "bring me water" then when he/she leaves you just log out of his/her account and if they made "Remember my password" ticked in Chrome user name and password will be brought on. You can now see the username and password like dots or *. Then you open inspect elements and under code "password" you change "password" to anything. And vuola ---- you are able to see the password. This can be done on any login page they have marked save password. This is serious problem regarding security.

Great to be part of the team :)

VERSION
Chrome Version: [<49.0.2623.87 m] + [stable]
Operating System: [Windows XP,7,8,8.1,10, Mac <OS X]


REPRODUCTION CASE

<input type="password" class="inputtext" name="pass" id="pass" tabindex="2">
***Password not visible***

<input type="asd(type anything)" class="inputtext" name="pass" id="pass" tabindex="2"> >>> ***Password visible*** !!!


FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [no crash]
 
Google password reveal.jpg
478 KB View Download
Status: WontFix (was: Unconfirmed)
Devtools is a client-side tool for debugging your own request and responses. There is nothing to hide there.
I think you are unaware of this situation!!!

I can go to my friend and tell him to bring me water or go to my car and see something,in the mean time I can see his/her password for every single site he has log in!!!

Everybody can access passwords like this! Gmail,Facebook,Twitter,...EVERYTHING !

Also have you saw picture? I think you are doing this routinely! 
Project Member

Comment 4 by sheriffbot@chromium.org, Jun 21 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 6 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment