New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 594997 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Chome accessing other user's information and sharing

Reported by fattirer...@gmail.com, Mar 15 2016

Issue description

After my pc went through an update last night, which updates were performed I am not cure, I tried to login to Facebook. When I pulled up Facebook using Chrome, another user's email and password were loaded in the login fields. Out of curiosity into how this could have occurred I attempted to login. Facebook recognized the username/password combination, but because the password was outdated, login was denied. But, the credentials corresponded to an actual user. After some investigating, I discovered that the user was an old contact I have stored in my phone from a company I worked with in the past. I do not know how or why my desktop pc would be able to pull that contact's personal email address and password and apply it into Facebook.

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs


VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.

VERSION
Chrome Version: Version 49.0.2623.87 m
Operating System: Windows 10

REPRODUCTION CASE
I have included screenshots of what I found.
 

Comment 1 by mea...@chromium.org, Mar 15 2016

Labels: Needs-Feedback
Thanks for the report. Sounds like your contact information is synced. Can you confirm that's the case? 

Comment 2 by wfh@chromium.org, Mar 22 2016

Cc: rpop@chromium.org
Sounds like user signed in on a device that had previous stored passwords. Unless told otherwise by the user that this didn't happen I will close this bug shortly.

Comment 3 by wfh@chromium.org, Mar 22 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
deleted sensitive screenshots, and WontFix.
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment