New issue
Advanced search Search tips

Issue 676909 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Dec 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Incognito mode with facebook com leads to security issue

Reported by dharam.i...@gmail.com, Dec 24 2016

Issue description


VULNERABILITY DETAILS
Google chrome is unable to protect the user security as they promised in incognito mode.
I have recently update my chrome software and try to login with facebook.com in incognito mode and closed that facebook tab.
My one of friend has also tried to login with facebook.com in other incognito mode and I was surprised that my profile has opened in his incognito session. 
I have also observed that if I close all incognito tabs and then open facebook.com it works perfectly by asking me to login again but as soon as I remain that incognito session open and try to open other incognito session then it takes that other session data which leads to security problems.  

VERSION
Chrome Version: 55.0.2883.87 m (64-bit)
Operating System: Windows 7 professional, service pack 1 , 64-bit os

REPRODUCTION CASE
1:Open incognito mode and open facebook.com and login in that
2:close facebook tab and remain other websites tab open
3:open another incognito explorer session and open the facebook.com

 
Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
As noted on the Incognito mode home page:

"Pages you view in incognito tabs won’t stick around in your browser’s history, cookie store, or search history after you’ve closed all of your incognito tabs"

The "after you've closed all of your incognito tabs" bit is important.

Sign in to add a comment