New issue
Advanced search Search tips

Issue 685101 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2017
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Attempted theft of session from https://mail.google.com/mail/feed/atom

Reported by jm.acun...@gmail.com, Jan 25 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36

Steps to reproduce the problem:
If we access the url https://mail.google.com/mail/feed/atom in Internet Explorer 11 and enter a valid email account and any password,
To the third attempt Google sends you an email

Email received from Google:

Subject: Check blocked login attempt

Body: Hello Jose Maria,
Google just blocked someone from signing in to your Google account, jm.acuna73@gmail.com, from an application that could put your account in jeopardy.

Do not recognize this activity?
If you have not recently encountered an error while trying to access a Google service, such as Gmail, from a non-Google app, someone may have your password.

(a button to change the password appears)

______________________________________________________________________________________________

To consider:

1- Google warns you: an app that is not from Google may endanger your Gmail account

False: this is https://mail.google.com/mail/feed/atom

2- The message prompts to change the password

3- Only happens with IE (Chrome, Firefox, Opera, do not send email)

What is the expected behavior?
I think it should work just like if trying to access an account from the gmail website

What went wrong?
1- Google warns you: an app that is not from Google may endanger your Gmail account

False: this is https://mail.google.com/mail/feed/atom

2- The message prompts to change the password

Did this work before? N/A 

Chrome version: 55.0.2883.87  Channel: stable
OS Version: 6.3
Flash Version: Shockwave Flash 24.0 r0
 

Comment 1 by est...@chromium.org, Jan 25 2017

Status: WontFix (was: Unconfirmed)
This bug tracker is for problems with the Chrome browser, and it sounds like this is an issue with Gmail. To report feedback on Gmail, please select "Send feedback" from within the Settings menu in Gmail.

Good luck!
Ok, thanks!
Project Member

Comment 3 by sheriffbot@chromium.org, May 4 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment