New issue
Advanced search Search tips

Issue 615702 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 76735
Owner: ----
Closed: May 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: login to any account even after closing incognito windows just because to one small fault in chrome

Reported by ranjeets...@iisertvm.ac.in, May 29 2016

Issue description


VERSION
Google Chrome Version: Version 50.0.2661.102 (64-bit)

Operating System: [OS X EI CAPTION 10.11.4 (15E65)]

REPRODUCTION CASE
As we know that incognito windows do not save anything. Because of that function people use incognito windows when they login other computer(like in cyber cafe or friends computer). But I found one way to login in someone account if they use incognito windows. Steps are following. 

Step 1 : open a incognito windows and login to wifi [in my case it is Dell sonic wall]. a popup windows will open to show the status of login time.

Step 2 : Close the original incognito windows.[not popup window]
[problem in chrome is that the popup windows opened is not seems like incognito window]

Step 3 : invite someone and ask him to open new incognito window and login in gmail or facebook.
[popup window of wifi login is seems like normal window so people do not close that]

step 4 : close incognito windows.

Step 5 : Click on "SSLVPN Portal" in popup windows or open new incognito then new incognito will open.

Step 6: open gmail or facebook. the gmail will open without asking username or password.

I think the popup window should have different colour like actual incognito windows so that other people can find out that they have not closed all incognito windows.
 
3 login to security wall.png
399 KB View Download
4 login status popup windows open.png
475 KB View Download
8 login to gmail.png
474 KB View Download
10 close incognito.png
653 KB View Download
12 login to gmail [no password needed].png
665 KB View Download
i captured screen to show the but i cannot upload because of size constrain.. 

Comment 2 by mea...@chromium.org, May 31 2016

Mergedinto: 76735
Status: Duplicate (was: Unconfirmed)
Thanks for the report. Incognito mode cleans up only after all incognito windows are closed. You are right that popup windows don't have an incognito indicator, and this bug was reported earlier at  bug 76735 .

Note that incognito isn't a security feature: It's not intended to share the same computer between users. For that, you should use OS accounts. Please see https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-
Labels: allpublic
Project Member

Comment 4 by sheriffbot@chromium.org, Sep 14

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment