New issue
Advanced search Search tips

Issue 686761 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Chrome privacy security bug

Reported by jenson...@gmail.com, Jan 30 2017

Issue description

Dear Support, 

I found that the passwords i saved in google chrome is not safe. Anyone who is using my computer can hack my passwords within seconds using Firefox in option "Import data from another browser". Just select the option and select chrome and select password and click next its done. All my passwords i can see in Firefox. Even after i secure with password for sync. But cannot possible to import passwords from Firefox if it is password protected. Please see the attachment.

Regards,
Jenson 




This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://www.chromium.org/Home
/chromium-security/security-faq

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.

VERSION
Chrome Version: [x.x.x.x] + [stable, beta, or dev]
Operating System: [Please indicate OS, version, and service pack level]

REPRODUCTION CASE
Please include a demonstration of the security bug, such as an attached
HTML or binary file that reproduces the bug when loaded in Chrome. PLEASE
make the file as small as possible and remove any content not required to
demonstrate the bug.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace, registers, exception record]
Client ID (if relevant): [see link above]

 
Chrome security bug.pdf
260 KB Download
Status: WontFix (was: Unconfirmed)
Thanks for the report. This is working as intended since it is almost impossible to protect your data against someone who has physical access to your machine (they can take your hard drive and read all of the data on it).

Additionally, importing passwords from one browser to another is supported to help people who decide to change browsers.

Comment 2 by jenson...@gmail.com, Jan 31 2017

Dear Support, 

Thanks for your reply. I noticed in Firefox, if we protect the saved passwords using master password its impossible to transfer to other browser. And if is not protected we can easily transfer. I think this option will help people more than the current one in Chrome, since Google is more focusing on privacy and security. Personally i like to use Google chrome for browsing , but due to this issue i prefer Firefox for my financial things. Thanks for understanding.
Project Member

Comment 3 by sheriffbot@chromium.org, May 9 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment