New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 595562 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: May 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug-Security



Sign in to add a comment

Security: Same directory name used for ChromeOS guest mode after reboot

Reported by resea...@nightwatchcybersecurity.com, Mar 17 2016

Issue description

VULNERABILITY DETAILS
User's home directory remains the same after reboot in guest mode. While it maybe be backed by tmpfs, it would be nice to randomize.

VERSION
Chrome Version: 49.0.2623.95 (Official Build) (64-bit)
Operating System: ChromeOS 7834.60.0 (= Official Build) stable-channel parrot

REPRODUCTION CASE
Login to Chrome OS in guest mode. Go to "chrome://version". Observe the profile path being "/home/chronos/u-XXXXX". Reboot the Chromebook, and try again. The profile path remains the same.
 

Comment 1 by mea...@chromium.org, Mar 18 2016

Labels: OS-Chrome
Owner: mdempsky@chromium.org
Status: Assigned (was: Unconfirmed)
Matthew, can you please triage?

Comment 2 by mea...@chromium.org, Mar 21 2016

Cc: kerrnel@chromium.org

Comment 3 by wfh@chromium.org, Mar 23 2016

Components: UI>Browser>Profiles
Labels: Security_Severity-Low Security_Impact-Stable
seems nice a nice to have, but I think this is at most Low, if not Lower than Low.
Project Member

Comment 4 by sheriffbot@chromium.org, May 4 2016

Labels: Pri-2
Cc: ya...@nightwatchcybersecurity.com
Cc: jorgelo@chromium.org mnissler@chromium.org
Owner: kerrnel@chromium.org
mnissler@/jorgelo@, what do you think? Is this a security bug? I don't see any evidence this is exploitable.
I don't know how you'd exploit this to do anything useful.
Should we just close this?
Status: WontFix (was: Assigned)
Project Member

Comment 10 by sheriffbot@chromium.org, Sep 5

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment