New issue
Advanced search Search tips

Issue 636086 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Gmail Password Reset Bug

Reported by t.johns9...@gmail.com, Aug 9 2016

Issue description

This requires account access which could be obtained from a computer left open, etc. By viewing when the password was last changed you can reset the password if they have never changed it by stating when the account was made. 

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Password reset based upon account creation. Requires account access. 

VERSION
Chrome Version: 52.0.2743.116
Operating System: Windows 10

 
Status: WontFix (was: Unconfirmed)
This doesn't seem be a Chrome bug report. Even if it was, it requires physical access -- please see https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-

It also looks like you may have uploaded the wrong image -- I've deleted it in case it contained confidential/personal information.
Labels: -Restrict-View-SecurityTeam

Sign in to add a comment