New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 617868 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security Bug : Normal mode for Chrome login doesn't require password when any supervisor mode account is deleted.

Reported by rh...@uci.edu, Jun 7 2016

Issue description

VULNERABILITY DETAILS
Normal mode for Chrome login doesn't require password when any supervisor mode account is deleted.

We tried adding a new user for Chrome as a supervisor and tried to delete it. The following things didn't happen as expected.
1. No password was required to delete the account
2. Upon removal of user, the normal mode is automatically logged in back, which is a critical security issue.

VERSION
Chrome Version: 50.0.2661.102 + stable
Operating System: [Mac OSX El Capitan]

REPRODUCTION CASE
The bug can be reproduced manually. Please create a new user in supervisor mode and then try to delete it. No password will be asked and Chrome browser will automatically log on to the original account back.

 
bug.mp4
1.5 MB Download
Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
This is working-as-intended.  The supervised user functionality in Chrome is not a security feature.  If you want a real security boundary, use your OS's account management and log in as separate users.
Cc: pam@chromium.org nepper@chromium.org
Components: Services>SupervisedUser
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment