New issue
Advanced search Search tips

Issue 609655 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: showen cache passwords

Reported by zni...@gmail.com, May 5 2016

Issue description

VULNERABILITY DETAILS
when you change the code :
<input type="password" class="inputtext" name="pass" id="pass" tabindex="2" vk_1728b="subscribed">
to :
<input type="text" class="inputtext" name="pass" id="pass" tabindex="2" vk_1728b="subscribed">
then enter the password ( www.facebook.com for exemple )
you can login correctly ...
but when you repeat the same thing -report 3-4 /attached files - ( changing the code to: <input type="text" class="inputtext" name="pass" id="pass" tabindex="2" vk_1728b="subscribed"> ... then try to login ); for a second time you can get the password by just typing the first letter / or just click in the password case . 

VERSION
Chrome Version:  [50.0.2661.94 m] + [stable]
Operating System: [windows, 7 professional,pack 1]

 
report 1.PNG
150 KB View Download
report 2.PNG
149 KB View Download
report 3.PNG
187 KB View Download
report 4.png
163 KB View Download

Comment 1 by f...@chromium.org, May 6 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
Thanks for the report!

Chrome only masks passwords as a convenience, to prevent shoulder-surfing. It is not meant to be a security feature. You can learn more about this on our FAQ: http://www.chromium.org/Home/chromium-security/security-faq#TOC-What-about-unmasking-of-passwords-with-the-developer-tools-
Project Member

Comment 2 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment