New issue
Advanced search Search tips

Issue 596363 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Able to Sign-in into Google account without Re-entering the password

Reported by kcvel...@gmail.com, Mar 21 2016

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs


VULNERABILITY DETAILS
Re-enter password option doesn't work. Once I have singed into my account and then closed the tab the,  opened Gmail again, I was asked to re-enter password and then I clicked on "Sign in with a different account" option. There I was to Sign-in without password into my account. I have attached a video. 

VERSION
Chrome Version: [49.0.2623.87] + [m]
Operating System: [Please indicate OS, version, and service pack level]

REPRODUCTION CASE
Please include a demonstration of the security bug, such as an attached
HTML or binary file that reproduces the bug when loaded in Chrome. PLEASE
make the file as small as possible and remove any content not required to
demonstrate the bug.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace, registers, exception record]
Client ID (if relevant): [see link above]

 
Bug Recording-Incognito.mp4
1.1 MB Download
Bug Recording-Normal.mp4
776 KB Download

Comment 1 by kcvel...@gmail.com, Mar 21 2016

Operating System: [Microsoft Windows 7, Ultimate , and Service Pack 1 ]

Comment 2 by mea...@chromium.org, Mar 21 2016

Labels: Needs-Feedback
Status: WontFix (was: Unconfirmed)
Thanks for the report. I can't reproduce this behavior. It's possible that the signout page isn't clearing the cookies. Can you please try on a new Chrome profile?

In any case, it's very unlikely that this is a Chrome vulnerability so I'm closing the bug for now. If you can consistently reproduce the behavior, I suggest reporting this bug to Gmail instead.

Comment 3 by kcvel...@gmail.com, Mar 22 2016

Can you provide me the link to report to Gmail under VRP
https://goo.gl/vulnz

I'd recommend reading more about Google's VRP at https://www.google.com/about/appsecurity/reward-program/ first.
Project Member

Comment 5 by sheriffbot@chromium.org, Jun 28 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 6 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 7 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment