New issue
Advanced search Search tips

Issue 644989 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Sep 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Incognito mode in Chrome keeps my gmail account logged in

Reported by cryptex....@gmail.com, Sep 8 2016

Issue description

0. Open Google Chrome
1. I opened a new incognito window, 
2. entered site mail.google.com 
3. entered credentials for account other than one I use in no-incognito mode
4. I see my Gmail inbox of harshadsmane user
5. I closed this incognito window
6. I again open an incognito window
7. entered site mail.google.com 
8. I see my gmail inbox of harshadsmane user without gmail asking me to enter credentials

This clearly means that Chrome is actually storing cookies and other user-data in incognito mode as well.

If I repeat same steps in FireFox private mode, i always need to enter my credentials, my session is not stored.

This is a very serious issue.
 

Comment 1 by wfh@chromium.org, Sep 8 2016

Labels: Needs-Feedback
Incognito mode stores cookies and persistent data until the last incognito window is closed, so if you open multiple windows they will share the same cookie jar.

https://support.google.com/chrome/answer/95464

Once the final incognito windows has been closed, then the cookies and persistent data are cleared.

Can you confirm which platform you are using?
Can you confirm which platform you are using?
- I am using Windows 7 latest version of Chrome
Status: WontFix (was: Unconfirmed)
I cannot replicate any such behaviour.  However, this is exactly what happens when your initial incognito session is still open.

As mentioned in the previous comment, you probably had some incognito window/process still running when you again opened incognito (step 6).

Thank you!
Project Member

Comment 4 by sheriffbot@chromium.org, Dec 23 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment