New issue
Advanced search Search tips

Issue 677830 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: images URLs in Hangouts are not Secured

Reported by anjanisa...@gmail.com, Jan 2 2017

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://www.chromium.org/Home
/chromium-security/security-faq

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.

VERSION
Chrome Version: [x.x.x.x] + [stable, beta, or dev]
Operating System: [Please indicate OS, version, and service pack level]

REPRODUCTION CASE
hai Google i have found a security problem with hangouts service..
when any user sends or receives a image via hangouts ...if he wants to open it he will click on image.. it will be open in a new tab..
and after logout from his account .. if any one came to the same system and if they click same URL used by hangouts user( for viewing image on perviously) by watching history ... that image will be visible for him.... that means there is ni securiry for the URL... it does'nt asking any login details... hope you will change it.. thanqqq and sorry for my English  

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace, registers, exception record]
Client ID (if relevant): [see link above]

 

Comment 1 by kenrb@chromium.org, Jan 2 2017

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
Thanks for the report, however this is not a problem with the web browser, it is a detail of how Hangouts handles media.

You are correct that knowledge of the URL is enough to access an image in hangouts, it is long and unguessable for that reason. From the point of view of the browser, it is not a good idea to let untrusted people have access to your logged in account on your computer, because sensitive information can accumulate in your profile.

As for the security of media in Hangouts, you can bring up your concern to Hangouts support and they might be able to respond with more information.
that means that URL will work after i sign out from my account.
ok then how can i talk with hangouts support team


Sign in to add a comment