New issue
Advanced search Search tips

Issue 678985 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 132135
Owner: ----
Closed: Jan 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: ----



Sign in to add a comment

Leak of users personal details through auto-fill and hidden inputs

Reported by depy45...@gmail.com, Jan 6 2017

Issue description

This template is ONLY for reporting privacy issues. Please use a different
template for other types of bug reports.

Please see http://www.chromium.org/Home/chromium-privacy for further
information.


PRIVACY ISSUE
The auto-fill feature provides a rich experience to users when filling out certain forms on websites, but using a few simple tricks any web page can easily compromise the privacy of a person taking the advantage of auto-fill. This can lead to leak of information like address, name, phone number and all the basic details that there are in an auto-fill.

VERSION:
Chrome Version: 55.0.2883.87 m + stable
Operating System: Windows 8

REPRODUCTION STEPS
If a form field is hidden, the auto-fill data is not set on those which is good. But using CSS' display property only applies here. We can bypass that by hiding a set of form fields inside a container element with 0 height and hidden overflow CSS property. 

A working demo has been created by me here - https://goo.gl/f8GfTB

Thanks. 

 
Mergedinto: 132135
Status: Duplicate (was: Untriaged)
Nice

Sign in to add a comment