New issue
Advanced search Search tips

Issue 664706 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Security Flaw

Reported by mustangm...@gmail.com, Nov 12 2016

Issue description


Hi. My name is Pedro Mesa and I enjoy surfing the web looking for security flaws and vulnerability's from websites and then reporting it. 


I recently found one with Gmail and Chrome.  

Before I get into it, I AM NOT AN EXPERT! I am just learning but I know that what I have found can be very dangerous and is probably being used by many people who have not reported it yet or maybe no one knows about it and I am the only one who actually came across by it. To be sincere i came across to this security flaw by accident meaning anyone else can come to it as well. 


Since I am not an expert the only way i can show you the security flaw is by making a video (I'll post the video on "Private" on youtube just so you can see it, with commentary. Once i make the video you will see why it is so important to fix this issue as it could be affecting MILLIONS of gmail & chrome users. 


I am poor. I have $0 to my name and I do want a reward. I do not want no hall of fame because I'm tired of applying at jobs and no one hiring me or even giving me a opportunity after Interviews. I've had jobs before and excelled on each and everyone one but now people judge you too much so its harder. 


Anyways, I want a nice reward, by nice I'm talking about 50k+ or even 400k
I understand that is pocket change to Google therefore that's what i really want in order to start my own business or something, I'm tired of sitting at home and depending on my family when they can barely depend on themselves. Its frustrating and none of you know the feeling since your reading this right now. 


If you would like me to make the video and showing the security flaw let me know and also let me know how much ill be compensated. I will not make my compensating public if thats what your worried about. I have no friends and i can keep everything to my self. 


Thank you.

Sincerely,

Pedro Mesa 
 

Comment 1 by rickyz@chromium.org, Nov 14 2016

Status: WontFix (was: Unconfirmed)
Hi, our normal process for handling security bugs is:

1) The reporter provides details of the bug
2) We fix the bug
3) If eligible, the bug goes to a committee to decide a reward amount.

Unfortunately, we are not able to guarantee any reward amount at this point. If you would like to report your bug regardless, please feel free to open a new bug.
Project Member

Comment 2 by sheriffbot@chromium.org, Feb 20 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment