New issue
Advanced search Search tips

Issue 596265 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: It's possible to see saved passwords in your browser without authentication

Reported by krystian...@gmail.com, Mar 19 2016

Issue description

VULNERABILITY DETAILS
It's possible to see saved passwords in your browser without authentication

VERSION
Chrome Version: [49.0.2623.87] + [stable]
Operating System: [Windows 7, Home Premium, Service Pack 1]

REPRODUCTION CASE
Normally to see saved passwords we have to open chrome://settings/passwords and after clicking a button attached to password we have to type Window's user's password, but we can bypass this by using simple method:
1. Read the username and site's address.
2. Open a site
3. Type username in login input
4. Password should appear but still encrypted
5. Now to see a password as plain text we just have to change input type from password to text in the html editor and we see our saved password (It probably works on every site like Facebook.com or Gmail.com)

 

Comment 1 by mea...@chromium.org, Mar 20 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
Please see this link as to why this isn't a vulnerability:
https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model- as to why this isn't a vulnerability.
Project Member

Comment 2 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment