Issue metadata
Sign in to add a comment
|
Security: Password Reset vulnerability
Reported by
lawlietx...@gmail.com,
Apr 9 2016
|
||||||||||||||||||
Issue descriptionThis template is ONLY for reporting security bugs. If you are reporting a Download Protection Bypass bug, please use the "Security - Download Protection" template. For all other reports, please use a different template. Please see the following link for instructions on filing security bugs: http://www.chromium.org/Home/chromium-security/reporting-security-bugs VULNERABILITY DETAILS Please provide a brief explanation of the security issue. VERSION Chrome Version: [Version 49.0.2623.110 m] + [stable, beta, or dev] Operating System: [windows 8.1] REPRODUCTION CASE https://support.google.com/accounts/troubleshooter/2402620?p=ar_other_problems&hl=en&rd=1#ts=2402552 the password assistance page is so vulnerable that anyone who knows a particular email can get into it.the date of creation and the last login date + the last known password is easy to bypass.i tried it using my email and i was able to reset my password even though i've put in details that were really not even close to the requirements.it didnt even ask me the security question and i just chose the "cant access phone" option for verifying it using my mobile phone number.i hope we can find a much secure way to get their login details as this could lead to lots of emails being hacked.
,
Jul 16 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by kenrb@chromium.org
, Apr 9 2016