New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 687066 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Feb 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 2
Type: Bug-Security



Sign in to add a comment

Chrome should not synchronize opened page opened in one profile on one machine to another profile on another machine

Reported by ikariena...@gmail.com, Jan 31 2017

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.95 Safari/537.36

Steps to reproduce the problem:
1. Create two profiles (profile X, profile Y) on one machine (machine A);
2. Sync profile X on another machine (machine B).
3. Open a page on machine A using profile Y.

What is the expected behavior?
A link to this page is not shown on machine B.

What went wrong?
A link to this page is shown in machine B. When clicked, it is opened using profile X. This is a potential security issue if profile Y is an enterprise profile that is indented to be used to access certain concealed URLs.

Did this work before? N/A 

Chrome version: 55.0.2883.95  Channel: n/a
OS Version: OS X 10.12.2
Flash Version:

 
Components: UI>Browser>Profiles Services>Sync
Owner: rpop@chromium.org
Status: Assigned (was: Unconfirmed)
mac triage: rpop@, you're the listed point of contact for sync. Can you route this?

Comment 3 by rpop@chromium.org, Feb 2 2017

Cc: zea@chromium.org ew...@chromium.org
Owner: gangwu@chromium.org
That definitely shouldn't happen. Routing to sync team to attempt to repro.

Comment 4 by ew...@chromium.org, Feb 2 2017

Just to make sure I understand the repro steps, let me ask some clarifying questions:

1. Create two profiles (profile X, profile Y) on one machine (machine A) - are you signing into Chrome and enabling Sync with different accounts in both profile X and profile Y? Assuming that's the case, let's call them account X and account Y (corresponding to their profile names).
2. Sync profile X on another machine (machine B) - does this mean you're signing into Chrome with account X in a new profile on machine B?
3. Open a page on machine A using profile Y - just to make sure I understand, you're just opening a new tab in profile Y and navigating somewhere?
4. A link to this page is shown in machine B. When clicked, it is opened using profile X - can you clarify what this means? Where is this link shown? Are you going to the "Tabs from other devices" section of the history page? And how is it being opened using profile X on machine B? Profile X is on machine A.

Comment 5 by ew...@chromium.org, Feb 2 2017

Labels: Needs-Feedback

Comment 6 by ew...@chromium.org, Feb 6 2017

Status: Unconfirmed (was: Assigned)
Friendly ping on the feedback that's been requested. We can't make progress until you provide answers to my questions above.
Project Member

Comment 7 by sheriffbot@chromium.org, Feb 7 2017

Status: Assigned (was: Unconfirmed)
Labels: -OS-Mac OS-All
Sync team: Can you please try to repro on the assumptions that:

* machine A, profile X is syncing with account foo@gmail.com
* machine A, profile Y is not syncing
* machine B, profile X is syncing with account foo@gmail.com

If any action in profile Y on machine A affects B/X, then we have a bug. Otherwise, I don't think we do, and we can close this unless the reporter provides more information.

Thanks!

Comment 9 by ew...@chromium.org, Feb 9 2017

Gang, can you please try following the repro steps with the assumptions listed above?

Assuming there's no issue, feel free to close this out.
1. Create two profiles (profile X, profile Y) on one machine (machine A) - are you signing into Chrome and enabling Sync with different accounts in both profile X and profile Y? Assuming that's the case, let's call them account X and account Y (corresponding to their profile names).

Yes. They are on difference profiles. I do not know you can have multiple accounts in the same profile.

2. Sync profile X on another machine (machine B) - does this mean you're signing into Chrome with account X in a new profile on machine B?

This is the only profile on machine B.

3. Open a page on machine A using profile Y - just to make sure I understand, you're just opening a new tab in profile Y and navigating somewhere?

Yes.

4. A link to this page is shown in machine B. When clicked, it is opened using profile X - can you clarify what this means? Where is this link shown? Are you going to the "Tabs from other devices" section of the history page? And how is it being opened using profile X on machine B? Profile X is on machine A.

No. There is an extra icon shown to the left of the taskbar (Dock) in machine B. Since machine only has account X, this should not happen at all. Apparently it's called Handoff by Apple: https://support.apple.com/kb/PH18754?locale=en_GB

Comment 11 by ew...@chromium.org, Feb 10 2017

I'm still not sure I understand the last part. How does the extra icon to the left of the taskbar have to do with the URL you're loading in profile Y on machine A?

Can you please add some screenshots to help clarify?
I'm opening a page on machine A using profile Y. Then an icon pops up in machine B. If I click on the icon, a chrome window is opened with machine B, that opens the page on machine A.

I think it's actually doing this through iCloud. Not sure if this is a Chrome issue anymore.

Comment 13 by ew...@chromium.org, Feb 10 2017

Status: WontFix (was: Assigned)
Yeah, that sounds like an iCloud mechanism based on the repro behavior you're describing and where the icon is being surfaced. Closing this out as WontFix.
Project Member

Comment 14 by sheriffbot@chromium.org, May 19 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment