New issue
Advanced search Search tips

Issue 667161 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 126398
Owner: ----
Closed: Nov 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Security issue with Google Chrome remember password function.

Reported by anhduc0...@gmail.com, Nov 21 2016

Issue description


VULNERABILITY DETAILS
Security issue with Google Chrome remember password function.
With Google Chrome remember my passwords function, anyone that has access to the browser for a brief amount of time can figure out the exact password for any account of the owner.
This security issue can occur when someone lend a friend/family member/stranger his/her computer with Google Chrome saving his/her accounts passwords, even if the person remember to sign out of all of his/her accounts before lending the computer. Anyone cam simply go to a website that requires logging in with an account, use google chrome's auto fill in function to have the ID and password displayed. Right click on the password bar (all the letters are hidden because it is a password), click on Inspect element, change the type="password" to type="text". Then the password will show.

VERSION
Chrome Version: Version 54.0.2840.98 (64-bit)
Operating System: [MAC OS and Windows of recent versions]

REPRODUCTION CASE
1. Borrow a someone's computer. The owner has logged out of all his/her accounts on chrome.
2. Launch Chrome.
3. Open a website that you know the owner has an account.
4. Click on ID tab.
5. Input a letter until chrome suggests the owner's ID. Click on the ID.
6. Chrome will auto fill the ID and password tab.
7. Right click on the password tab, click on Inspect Element.
8. Change the phrase type="password" to type="text". Or if you are feeling like a 5 year-old, change it to type="1234".
9. Password tab now shows the password in text.
 
ISSUE.
 No encryption is present at this end (user's end) of the Chrome remember my password function. It's like putting a huge diamond in a maximum security safe and then taking it out and give it to the owner on the corner of the street.
 Solution proposal: 
+ Disable the inspect element function for password tabs. 
+ When users use the auto fill function, mask the password bar with an additional security measurement.

Note:
I hope this security bug is not too minimal for you guys. It is one that I have tried many times on my friends and all of them has been very concerned after I showed them.


 

Comment 1 by mea...@chromium.org, Nov 21 2016

Labels: -Restrict-View-SecurityTeam allpublic
Mergedinto: 126398
Status: Duplicate (was: Unconfirmed)
Please see https://dev.chromium.org/Home/chromium-security/security-faq#TOC-What-about-unmasking-of-passwords-with-the-developer-tools-

Sign in to add a comment