New issue
Advanced search Search tips

Issue 663398 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Developer tools allow saved passwords to be displayed

Reported by b.hamilt...@gmail.com, Nov 8 2016

Issue description

VULNERABILITY DETAILS
Using console tools in Chrome, one can simply change the input type from 'password' to 'text' to show previously remembered passwords.

VERSION
Chrome Version: [54.0.2840.87 m] + [stable]
Operating System: [Windows 10 pro, 1607, 14393.351]

REPRODUCTION CASE
With 'manage passwords' enabled, Chrome remembers login and password details.  If you attempt to display a password in the settings menu, you are prompted for the windows password.

However, if you use Chrome to access a website (for which the password has previously been remembered) and then open the developer tools, you can simply change the input type from 'password' to 'text' to show previously remembered passwords.  

I think that the developer tools should prevent changing the input type from password otherwise the windows password request in the settings menu is falsely reassuring.

 

Comment 1 by wfh@chromium.org, Nov 8 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
https://www.chromium.org/Home/chromium-security/security-faq#TOC-What-about-unmasking-of-passwords-with-the-developer-tools-

Sign in to add a comment