New issue
Advanced search Search tips

Issue 673119 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug-Security



Sign in to add a comment

Logging in Gmail account without a password after user change.

Reported by popova1y...@gmail.com, Dec 10 2016

Issue description

Steps to reproduce the problem:
1. To clear data and cache in Chrome browser in the phone settings.
2. To open Gmail in Chrome browser on the link  https://www.google.com/gmail
3. To input the first e-mail adress and the password.
4. To close pop-up with asking to save the password.
5. To close tab with Gmail account.
6. To open a new tab Gmail in Chrome browser on the link  https://www.google.com/gmail
7. To click the link "Sign in to add another account"
8. To input the second e-mail adress and the password for it.
9. To pay attention in what account you are logged. 

What is the expected behavior?
Expected result 1: Logging on the account after inputing the data for this account.
Or Expected result 2: An error message about the impossibility to enter the new account until you sign out of the previous one.

What went wrong?
Actual result: Logging on the first account without a password for it after inputing data for the second account.

Did this work before? N/A 

Chrome version: 54.0.2840.68  Channel: n/a
OS Version: 4.2.1
Flash Version:
 
VID_20161210_182248_s01.mp4
7.5 MB View Download
 Issue 673120  has been merged into this issue.
Summary: Logging in Gmail account without a password after user change. (was: Logging in Gmail account without a password after user change.)
Video appears to match repro steps; I don't speak Russian(?) so I'm not sure what the yellow info bubble Gmail shows at the end of the video says. It's not clear if this is a Chrome issue or a Gmail issue.

Comment 3 Deleted

The yellow info bubble shows the Gmail info that I'm logged as popova1yuliya@gmail.com, but I input the datа (email and password) for another account - vobarkal@gmail.com. So, without saving the data in Chrome, I could to log in in the account without password.
Cc: melandory@chromium.org sabineb@chromium.org
Components: UI>Browser>Passwords
Hi Tanja, Sabine,

Could one of you help determine if this is a Chrome or Gmail issue?  Please feel free to add labels and CC anyone who might be better able to own this bug!

Thanks!

Comment 6 by wfh@chromium.org, Dec 20 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
This is not a Chrome issue, perhaps *at most* this is a gmail display bug. gmail allows multi-login so you can have multiple accounts logged in at the same time. you can switch between these accounts using the menu at the top left.

It looks like at most, gmail does not, by default, display the latest logged in account but instead the first logged in account... not a security vulnerability.

Comment 7 by wfh@chromium.org, Dec 20 2016

b/33786639 for tracking

Sign in to add a comment