New issue
Advanced search Search tips

Issue 633522 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Closed: Aug 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Security: Google Chrome shows history of last used url in incognito window

Reported by anuraj...@gmail.com, Aug 2 2016

Issue description

VULNERABILITY DETAILS
When a user typed/visited a page url in normal chrome browser, same url history is showing suggestion in incognito window when we press single character in address bar.  

VERSION
Chrome Version: latest
Operating System: Windows 10

REPRODUCTION CASE
Open normal chrome browser.
type an url, hit enter.
open incognito window.
type first character of recently typed url in address bar.
in suggestions recently visited url will appear.


 
Components: UI>Browser>Incognito Privacy
Labels: -Restrict-View-SecurityTeam OS-Windows Pri-2
Owner: msramek@chromium.org
Status: Assigned (was: Unconfirmed)
Hi, thanks for the report. Issues with incognito are generally not considered security issues (please see https://www.chromium.org/Home/chromium-security/security-faq#TOC-Are-privacy-issues-considered-security-bugs-). 

I actually think this is working as intended but assigning to msramek to verify. Thanks!
Labels: -Type-Bug-Security Type-Bug
Status: WontFix (was: Assigned)
Correct, this is working as intended.

The idea is that the incognito profile is built atop of the regular one. In incognito, you can take advantage of most of the context from the regular profile, but not vice versa - the state from incognito must not be persisted.

You can take password manager as another example - in incognito, we will not offer you to save passwords, but you can always log using a password that you saved in the regular mode.

If you really need a fresh slate that does not carry over any context from your regular profile, consider using the guest mode (account selector in the top right corner > Switch person > Browse as guest).

Sign in to add a comment