New issue
Advanced search Search tips

Issue 658505 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Oct 2016
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Security threat

Reported by abeott...@gmail.com, Oct 22 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36

Steps to reproduce the problem:
1. Suppose you have current working system(System-A). and login to newly formatted system(System-B)(means new window os) using your gmail and "Chrome Remote desktop App".
2. you would find all your username ans passwords cookies of System-A will come to System-B
3. Now you logged out from system-B.
4. Your friend is having current system (System-C) and he tries to login into System-B using his gmail and "Chrome  Remote Desktop App" and logged out.
5. Now you can find all the cookies/UserName/Password of System-C in System-B and it has cookies/UserName/Password of System-A also.
6.Means on System-B cookies/UserName/Password of System-A and System-C is merged

What is the expected behavior?
It should not merge cookies/UserName/Password of different users.

What went wrong?
It merged cookies/UserName/Password of different users.
Please read story in comment section.
Now when you login to new system you would find merged cookies/UserName/Password of UserA and UserB.
UserA can login into any bank related site of UserB and can do the transaction, as password is getting auto-filled as we type username of UserB.
Similarly UserB can Hack system of UserA.

Did this work before? Yes Version 53.0.2785.143 m (64-bit)

Chrome version: 53.0.2785.143  Channel: n/a
OS Version: 6.2 (Windows 8)
Flash Version: Shockwave Flash 23.0 r0

A very big Security glitch in google chrome, it should be removed very fast. Now i can access all passwords and username of the users even I can login to another person bank account and transfer money to another account.

How i detected this glitch.
I always use chrome in my system. So chrome is having all my username and password as cookies or whatever you say.
Means when i open a site i can login into site without typing username ans password, because chrome is saving all username and password.

Then I got a new laptop and i logged in using gmail and then i was trying to use "Chrome Remote Desktop" App. I logged into that app. At that time i saw i was having all the username and password. So In new laptop i was having all username and password of my old system. I was happy as i was thinking google recognise me on another (New Laptop)system also and helps me use username and password.

Next thing happened i logged out from new laptop (gmail and Chrome Remote Desktop app). My friend tried to logged in gmail and "Chrome Remote Desktop app" as he was trying to make some systems online on internet. He used my laptop completed his work and logged out from new laptop. 
Next day i found that on new laptop i was having all cookies of my friends username/Password to my google chrome. Even my username and passwords also has been merged with my friends username and password.

Even now when i login to gmail and chrome to new system(it may be mac or desktop) , i am having merged(I+my friend) username and password.

Means suppose I use siteA and for login, i have username "UserA" and same site my friend is using and he is having Username "UserB".
there is auto-password fill option works in google chrome. Means when i select UserA or type UserA, my password gets auto-filled by google chrome.
same way when i type or select UserB , My friends passwords gets auto-filled by google chrome.

Now i have all the logging details of my friend. Even all the bank details(Username/Password) also. 

I think you guys can understand its very big security threat. Anybody can loose million of dollars because of this.
Please remove this threat from google chrome.

IF you reward me i will give you more security glitches.

Thanks,
My email-id is :- abeotttyy@gmail.com
other gmail is :- million.rahul@gmail.com
 
Labels: -Restrict-View-SecurityTeam allpublic
Status: WontFix (was: Unconfirmed)
This is working as intended. See https://support.google.com/chrome/answer/185277?hl=en for more information about sync, and how to avoid this kind of issue when using it.

On a side note, we generally don't classify issues that require physical access to a device to be security bugs. See https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model- for more information.

Comment 2 by abeott...@gmail.com, Oct 22 2016


Please  check my comments, now the cookies and passwords are merged.
if i am using new system and login using my gmail, what you can  see i am getting another people user name passwords to my  system. 
Now i can login to their paypal account and transfer money to anywhere.
Dont you see that how risky it is??????

Comment 3 by abeott...@gmail.com, Oct 22 2016

Dont you think there should be New changes like when person logs-out from system his cookies and password should be removed from that system.

Please dont think user would be smart enough to go somewhere in settings and changes setting for synchronisation username/passwords/auto-fill. They dont have time to do this stuff. they dont even have time to read the instructions also. But dont you think they will feel bad when they find that their privacy has been breached because of google chrome having default feature of merging/synchronisation username/passwords/auto-fill.

you  can give features of merging/synchronisation passwords/cookies. But dont do it by default.

Comment 4 by abeott...@gmail.com, Oct 23 2016

I think you guys wont do the anything, i have to take some steps to prevent this kind of fraud. 
I am posting this stuff to social-Media as i want to create awareness between people, But i am scared also as other people might misuse these feature of google-chrome.

https://twitter.com/Rush_time_help/status/789988372202655744
https://www.facebook.com/permalink.php?story_fbid=1591777231128397&id=100008884054510

By the way thanks for your response


Comment 5 by abeott...@gmail.com, Oct 23 2016

I have informed Facebook, twitter, pay-pal and different banks around the world to create the awareness. 

Sign in to add a comment