New issue
Advanced search Search tips

Issue 606111 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Signed in pages remain in signed in state after crash.

Reported by paragyer...@gmail.com, Apr 23 2016

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs


VULNERABILITY DETAILS
Hi,
I want to report a security issue where after Chrome crash the signed in pages remain in signed in state. I had few HTTPS sites which should ideally be logged out after crash. 

VERSION
Chrome Version: [49.0.2623.112 m] + [stable, beta, or dev]
Operating System: [Win 7 Professional, Service Pack 1]

REPRODUCTION CASE
On this chrome version every crash doesn't logs off the site.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [browser]
Crash State: [see link above: stack trace, registers, exception record]
Client ID (if relevant): [see link above]

 

Comment 1 by vakh@chromium.org, Apr 25 2016

Status: WontFix (was: Unconfirmed)
Hello, thanks for reporting this but this is likely working as intended.
A crash is not expected to clear persistent cookies but should clear session cookies.
Can you please share more details about what kind of cookies are not getting cleared and also share a proof-of-concept?

Please feel free to re-open the bug with a proof-of-concept.
Project Member

Comment 2 by sheriffbot@chromium.org, Aug 2 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment