New issue
Advanced search Search tips

Issue 619576 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 614301
Owner: ----
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: ----
Type: Bug



Sign in to add a comment

Reopen Closed Tabs feature is compromising the Privacy and Security

Reported by readings...@gmail.com, Jun 13 2016

Issue description

VULNERABILITY DETAILS

VERSION
Chrome Version: [51.0.2704.84 m]
Operating System: [Windows, 8.1 pro]

REPRODUCTION CASE
Launch Google Chrome Browser
Open some websites in separate tabs
While these tabs are still opened,Navigate to History 
Click Clear Browsing Data
Select "the beginning of time" in the dialogue box
Check mark all tabs to clear everything such as browsing history,cache,forms etc
Close the browser when everything is removed
Open a new chrome instance now
Press Ctrl+Shift+T

EXPECTED OUTCOME:
No previously accessed tabs should be opened on pressing Ctrl+Shift+T because the user has removed the history and cleared the cache.

ACTUAL OUTCOME:
The tabs that are opened while history removal process are still open-able and recoverable after history removal and closing the browser.

Sever Impacts:
This behavior of the Reopen Closed Tab feature may lead towards leakage of the confidential accessed pages, and as a result spoiling the privacy completely.
The above mentioned behavior can have a negative impact on the followings
-security of banking websites specially if there is no proper mechanism of session expiry.
-disclosure of sensitive data of govt officials when they use public computers.
-privacy of a person is the most applicable concern due to this bug.

Possible Solution:
While the history is getting removed, the Chrome should discard all the paths of current opened webpages.


 
Cc: yitingc@chromium.org
Components: Privacy
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Summary: Reopen Closed Tabs feature is compromising the Privacy and Security (was: Security: Reopen Closed Tabs feature is compromising the Privacy and Security )
This is not a security issue, since the act of clearing history doesn't define a security boundary, but it does seem like it could surprise users.  Kay -- Is this a known issue?
Then Kindly explain What the Chrome will do for safeguarding the privacy of users in this regards? 
If this is not a security issue then it must be a privacy issue? Whats
your stance on it?
Labels: OS-Windows
Mergedinto: 614301
Status: Duplicate (was: Unconfirmed)
Thanks for flagging this for privacy.
This has been reported before and we are looking into it. Please follow  Issue 614301 .

Sign in to add a comment