New issue
Advanced search Search tips

Issue 594939 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Opera Browser takes over Chrome sessions

Reported by tobias.f...@gmail.com, Mar 15 2016

Issue description

After installing Opera Browser with a Chrome Browser installed on my PC, Opera was able to take over all current sessions from my Chrome browser: I was auto logged in in Google, Facebook. 


VULNERABILITY DETAILS
I have been using the same Windows user profile. I am logged in to Google Chrome using my Google account. Synchronization of passwords and bookmarks is enabled. I personally don't want to allow any software using the Blink engine to access these session details stored in Chrome browser. Therefore, I suppose this behaviour as a security bug. 

VERSION
Chrome Version: 48.0.2564.116 m
Opersa Version: 35.0.2066.92
Operating System: Microsoft Windows 10 Education Edition, 64 bit 

REPRODUCTION CASE
To reproduce the case, I need to install Google Chrome and to initialize a few sessions on services like Google, Facebook or others. Next I install Opera browser and open it after the installation process succeeded. Opening the websites above, results in logged in sessions. 

 

Comment 1 by mea...@chromium.org, Mar 15 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
Chrome cannot defend against from programs running with the same privileges, so there isn't anything actionable for us to do here. Please see https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model- as to why this is outside Chrome's threat model.

I'm not sure if this is intended behavior by Opera, you might want to file a bug at https://bugs.opera.com if you believe it is.
I can confirm that this is intended behaviour on Opera's part. On first start, Opera imports the session, cookies and other data to make the transition from whichever browser was set as default as seamless as possible.
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment