Issue metadata
Sign in to add a comment
|
Security: Access to ALL autocompleted passwords
Reported by
morissa...@gmail.com,
Nov 25 2016
|
||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS - The security vulnerability is base on the fact that login/password in HTML form are auto-complete is Chrome has enable this option (activated by default). - The live rendering of the HTML page is the problem, if i edit the HTML code on my chrome page, i'm able to read ALL auto-completed passwords. If i have access to a user session, i can get a lot of login/passwords very quicky. Just navigating on major webSites. On macOS, password are stored in keychain. The security is strong because password session is required to access keychain data. On Chrome ... if the password is autocomplete ... password are NOT safe. VERSION Chrome Version: 54.0.2840.98 (64-bit) stable AND probably all versions Operating System: MacOS 10.11.6 (15G31) AND probably all OS REPRODUCTION CASE 1. Take a friend user sessions opened 2. Navigate to any important website, GMAIL, FACEBOOK, WHATAPPS. 3. Disconnect you from the service if it's already connected 4. If the login/password is auto-complete, the job is done! 5. Click on the form, inspect HTML, change input type from "password" to "text" 6. The live rendering is done, you have the password ! By using this i was able to get my girl friend's passwords and i was able to get back my mission password which were protected by google.password (without using my google credentials)
,
Nov 25 2016
Really ? Ok, I'm going to write an article about that, it's a huge problem. Peoples should know/understand that a unlocked session is really a important risk to allows an open access to a lot a login/password. Best regards, Jerome
,
Mar 3 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by dominickn@chromium.org
, Nov 25 2016