New issue
Advanced search Search tips

Issue 615726 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jun 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Security: Incognito history is traceable by other apps.

Reported by sasidhar...@gmail.com, May 29 2016

Issue description

Private/Adult content watched in incognito mode being displayed in CM security app as warning 'adult contect' ..

This makes the purpose of incognito mode useless .

Replication steps:
Watch xvideos in incognito(careful here 
 
Screenshot_20160530-010247.png
357 KB View Download
Screenshot_20160530-010355.png
181 KB View Download
Screenshot_20160530-010404.png
37.6 KB View Download
I meant to say ... TRACEABLE in the summary.

Comment 2 by mea...@chromium.org, May 31 2016

Components: Privacy
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
I believe that app has necessary permissions to view other app activity and Chrome can't defend itself in such a scenario. Adding privacy label and dropping from security queue.

Comment 3 by mea...@chromium.org, May 31 2016

Summary: Security: Incognito history is traceable by other apps. (was: Security: Incognito history is taxable by other apps.)
No I doesn't .. It's just after the recent update..

Can u check it on your end once... it's seems to be a serious issue. Like how can someother app trace chrome history when chrome itself is not supposed to.
Could you explain which CM Security app you have installed so that I can investigate? There seem to be several ones with different permissions.
Attached the app info screenshot from my phone. Am not updating the app as the new updates might cover up this issue. This isn,t accepted as u can clearly see i have given any permision on my browing related stuff.
Screenshot_20160603-202946.png
75.6 KB View Download
typo - meant to say "I havenot* given any permission"
We are still trying to understand this. The last screenshot shows a search for xvideos, not a visit to the site. Is it possible that you searched for xvideos in regular mode and then opened the website in incognito mode?
https://drive.google.com/file/d/0BzndUIYsEMcSN0R4NDV3c3Jlclk/view?usp=drivesdk

Above is the link to the video that I have recorded on my phone... hope that helps
Sorry for the nude content... tried my best to minimize it. 
Thank you very much. I have reached out to our security experts again.
Another follow up question. Have you rooted your device or is this a genuine Android?
That is genuine Android .. Did not root my phone 
Just am curious here. Any progress so far. Did we get the root cause. Need any inputs?
Some people are investigating in the background. I'll update the ticket as soon as there is news.
Thanks ... is this replicable, I mean are u guys able to replicate this issue.
not always but often
Ok thanks....
Is the status still 'unconfirmed'. Isn't it a valid bug.
Owner: battre@chromium.org
Status: Started (was: Unconfirmed)
Thanks for the quick updates...

Just I have one more doubt left .. Can this be considered eligible for a bounty.
Status: WontFix (was: Started)
Here is what the situation seems to look like.

We have not found any evidence that browsing history entries from incognito mode are left by Chrome. However, we have observed that CM Security uses the accessibility interface of Android to monitor the Chrome URL bar. When you have enabled the accessibility APIs you should have seen a scary warning explaining you that software can see what your doing on the phone. It is possible that CM Security monitors and records your browsing history in incognito mode and offers you to delete the records from their own database. When you disable the accessibility API access, you should notice that CM Security does not warn you about traces left in your browsing history. There is an ongoing debate whether Anti Virus software is snakeoil, and whether it is harming users more than helping. I am not going to comment on that.

I have sent an email to cmsecurity@cmcm.com on June 13 but haven't heard back.

At this point, we see no indication that Chrome or Android are doing anything wrong and leaving traces.
Ok .. Thanks
But shouldn't this "CM Security uses the accessibility interface of Android to monitor the Chrome URL bar." thing be restricted in incognito mode as whatever done in incognito has be incognito. 
No, in that case we would deprive all users that require accessibility features of using incognito mode.
Got any reply from CMsecurity on this
I have received a response from CM Security today and they will stop this behavior in the next release. Thanks for reporting this.
Thanks for the update..

The only reason for reporting this is that I was expecting it to be major privacy issue, as some other app was making misuse of a feature which I guess should not even be provided in the first place without my permission or at least notified. 

But the way this issue was handled just makes me feel unsafe and may be lose trust in one of the few tech companies that I believed were there to make a difference. And I guess I am wrong..

Anyways again thanks for your time. And hopefully in the near future at least please try to be incognito when you say incognito...

Sign in to add a comment