Issue metadata
Sign in to add a comment
|
Security: Able to Sign-in into Google account without Re-entering the password
Reported by
kcvel...@gmail.com,
Mar 21 2016
|
||||||||||||||||||
Issue descriptionThis template is ONLY for reporting security bugs. If you are reporting a Download Protection Bypass bug, please use the "Security - Download Protection" template. For all other reports, please use a different template. Please see the following link for instructions on filing security bugs: http://www.chromium.org/Home/chromium-security/reporting-security-bugs VULNERABILITY DETAILS Re-enter password option doesn't work. Once I have singed into my account and then closed the tab the, opened Gmail again, I was asked to re-enter password and then I clicked on "Sign in with a different account" option. There I was to Sign-in without password into my account. I have attached a video. VERSION Chrome Version: [49.0.2623.87] + [m] Operating System: [Please indicate OS, version, and service pack level] REPRODUCTION CASE Please include a demonstration of the security bug, such as an attached HTML or binary file that reproduces the bug when loaded in Chrome. PLEASE make the file as small as possible and remove any content not required to demonstrate the bug. FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION Type of crash: [tab, browser, etc.] Crash State: [see link above: stack trace, registers, exception record] Client ID (if relevant): [see link above]
,
Mar 21 2016
Thanks for the report. I can't reproduce this behavior. It's possible that the signout page isn't clearing the cookies. Can you please try on a new Chrome profile? In any case, it's very unlikely that this is a Chrome vulnerability so I'm closing the bug for now. If you can consistently reproduce the behavior, I suggest reporting this bug to Gmail instead.
,
Mar 22 2016
Can you provide me the link to report to Gmail under VRP
,
Mar 22 2016
https://goo.gl/vulnz I'd recommend reading more about Google's VRP at https://www.google.com/about/appsecurity/reward-program/ first.
,
Jun 28 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by kcvel...@gmail.com
, Mar 21 2016