New issue
Advanced search Search tips

Issue 644986 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Sep 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Password of saved credentials can be visible from Developer's mode

Reported by suptikan...@gmail.com, Sep 8 2016

Issue description


VULNERABILITY DETAILS
When a user logs into any of the sites in Chrome browser, the user is prompted to save the credentials by Google. If the user opts for saving it, then the next time user visits that site, he/she does not have to provide the credentials. The user just has to click on Login or Submit or Sign Up button. But in this scenario, if some other user is using the system, he/she can get the password details by going into the developer's mode.
Usually, for the password field, the HTML input tag used has an attribute "type=password". If someone changes it to "type=text", then the password is clearly visible. Hence the user is vulnerable to sort of giving away his/her password to someone.

VERSION
Chrome Version: All version of Chrome
Operating System: NA

REPRODUCTION CASE
1. Open Gmail
2. Log into your account
3. Google will prompt for save credentials options. Click on Yes to save the credentials.
4. Log out of Gmail
5. Again go to Gmail page. You will find your credentials highlighted with password section showing * or dot symbol.
6. Right click on password field and click on Inspect. Developer mode of the browser will open.
7. Change the input tag attribute i.e, "type=password" to "type=text"
8. User's password will be visible
Attached is the screenshot for reference.

 

Comment 1 by wfh@chromium.org, Sep 8 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
http://www.chromium.org/Home/chromium-security/security-faq#TOC-What-about-unmasking-of-passwords-with-the-developer-tools-

Sign in to add a comment