Issue metadata
Sign in to add a comment
|
Security: Security issue with Google Chrome remember password function.
Reported by
anhduc0...@gmail.com,
Nov 21 2016
|
||||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS Security issue with Google Chrome remember password function. With Google Chrome remember my passwords function, anyone that has access to the browser for a brief amount of time can figure out the exact password for any account of the owner. This security issue can occur when someone lend a friend/family member/stranger his/her computer with Google Chrome saving his/her accounts passwords, even if the person remember to sign out of all of his/her accounts before lending the computer. Anyone cam simply go to a website that requires logging in with an account, use google chrome's auto fill in function to have the ID and password displayed. Right click on the password bar (all the letters are hidden because it is a password), click on Inspect element, change the type="password" to type="text". Then the password will show. VERSION Chrome Version: Version 54.0.2840.98 (64-bit) Operating System: [MAC OS and Windows of recent versions] REPRODUCTION CASE 1. Borrow a someone's computer. The owner has logged out of all his/her accounts on chrome. 2. Launch Chrome. 3. Open a website that you know the owner has an account. 4. Click on ID tab. 5. Input a letter until chrome suggests the owner's ID. Click on the ID. 6. Chrome will auto fill the ID and password tab. 7. Right click on the password tab, click on Inspect Element. 8. Change the phrase type="password" to type="text". Or if you are feeling like a 5 year-old, change it to type="1234". 9. Password tab now shows the password in text. ISSUE. No encryption is present at this end (user's end) of the Chrome remember my password function. It's like putting a huge diamond in a maximum security safe and then taking it out and give it to the owner on the corner of the street. Solution proposal: + Disable the inspect element function for password tabs. + When users use the auto fill function, mask the password bar with an additional security measurement. Note: I hope this security bug is not too minimal for you guys. It is one that I have tried many times on my friends and all of them has been very concerned after I showed them. |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by mea...@chromium.org
, Nov 21 2016Mergedinto: 126398
Status: Duplicate (was: Unconfirmed)