New issue
Advanced search Search tips

Issue 668631 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Access to ALL autocompleted passwords

Reported by morissa...@gmail.com, Nov 25 2016

Issue description

VULNERABILITY DETAILS
- The security vulnerability is base on the fact that login/password in HTML form are auto-complete is Chrome has enable this option (activated by default).
- The live rendering of the HTML page is the problem, if i edit the HTML code on my chrome page, i'm able to read ALL auto-completed passwords.

If i have access to a user session, i can get a lot of login/passwords very quicky. Just navigating on major webSites.

On macOS, password are stored in keychain. The security is strong because password session is required to access keychain data.
On Chrome ... if the password is autocomplete ... password are NOT safe.

VERSION
Chrome Version:  54.0.2840.98 (64-bit) stable AND probably all versions 
Operating System: MacOS 10.11.6 (15G31) AND probably all OS

REPRODUCTION CASE
1. Take a friend user sessions opened 
2. Navigate to any important website, GMAIL, FACEBOOK, WHATAPPS.
3. Disconnect you from the service if it's already connected
4. If the login/password is auto-complete, the job is done!
5. Click on the form, inspect HTML, change input type from "password" to "text"
6. The live rendering is done, you have the password !

By using this i was able to get my girl friend's passwords and i was able to get back my mission password which were protected by google.password (without using my google credentials)



 
Chrome-security-issue.png
219 KB View Download
Status: WontFix (was: Unconfirmed)
Physical access to your unlocked device with Chrome open is required to use Inspect in this way. Unfortunately, this is not a security vulnerability, since anyone with physical access to your unlocked machine can do basically whatever they like.
Really ? 
Ok, 

I'm going to write an article about that, it's a huge problem.
Peoples should know/understand that a unlocked session is really a important risk to allows an open access to a lot a login/password.

Best regards, 
Jerome
Project Member

Comment 3 by sheriffbot@chromium.org, Mar 3 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment