Issue metadata
Sign in to add a comment
|
Security: Reveal saved password in 10 seconds
Reported by
gravou...@gmail.com,
May 4 2016
|
||||||||||||||||||
Issue descriptionI noticed that on every login page (fb, google, yahoo...), when you are not connected and that Chrome knows your data (without displaying them of course), if you are a little curious by just inspecting the page you get this about the password: <input name="passwd" id="login-passwd" class="login-input pure-u-1" type="password" maxlength="64" tabindex="2" aria-required="true" placeholder="Password" title="Password" autocorrect="off" autofocus=""> And by just changing ""type=password" by "type=text" it shows the password...! VULNERABILITY DETAILS Its means that anyone who get access to the computer directly or via a VPN can reveal any passwords quite easily and that the settings/managing passwords is not secured at all. VERSION Chrome Version: 50.0.2661.94 (64-bit) Operating System: [MAC OS, El Capitan version beta 10.11.5] REPRODUCTION CASE Just do as explained before and you can see any passwords on any computer
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by rsesek@chromium.org
, May 4 2016Status: WontFix (was: Unconfirmed)