New issue
Advanced search Search tips

Issue 597939 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug-Security



Sign in to add a comment

I can see the other peoples password on some sites

Reported by vinaysiv...@gmail.com, Mar 25 2016

Issue description

Steps to reproduce the problem:
how to get somebody's password in less than 2 min 
Follow these simple instructions:
-REQUIRES A LOT OF SOCIAL ENGINEERING 
1.Erase all the saved email ID (not important)
2.Ask your friend to login in his/her account in your device using chrome 
3.Wait for them to logout
4.Next thing you want to do is double tap on the email id tab and    the victims email id will show up.
5.For the password tab put the tab on show mode then keep entering and removing each letter one by one until some word or something pops up
6.And there you go now you have total control over the account 

The Vedio for this is in the link below ,I tested this on a facebook test account and it still worked 

The vedio is kept unlisted so only few people can see this 

https://www.youtube.com/watch?v=CrEa_4CUjUU

What is the expected behavior?
What is happening is that the the phone is acting like a keylogger and when your friend or some persons logs in the phone records all the important stuff you already used in the past like your email ID and enters it on that tab.

What went wrong?
The device is recording  the password as a auto fill data which should not happen 

Did this work before? N/A 

Chrome version: 49.0.2623.87  Channel: n/a
OS Version: 
Flash Version: Shockwave Flash 21.0 r0
 

Comment 1 by wfh@chromium.org, Mar 25 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
Thanks for your report and video.

You should only log into a device that you fully trust. This is not a bug in Chrome, and is excluded as a physically local attack

https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-
Project Member

Comment 2 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment