New issue
Advanced search Search tips

Issue 697291 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2017
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Security



Sign in to add a comment

User related information shared through links forwarded mail through GMAIL

Reported by nandhaku...@gmail.com, Mar 1 2017

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36

Steps to reproduce the problem:
1. I have got a forward mail of a Job portal mail from one of my friend. That forward mail contains "Apply Now" option. So when my friend got that mail he can click on that mail and he can directly apply to that job without the need of logging in into the Job portal.

What is the expected behavior?
No

What went wrong?
As he forwarded me that mail and when i clicked on "Apply Now" option, i thought that job portal will ask me for login and then i have to apply. The reason is i have saved login credentials and password of that Job Portal in my Gmail account and it is linked with my Chrome browsers across the different systems. But instead of asking my Login Credentials, that link has proceeded logging in into my friend's credentials. This i found out when i saw the profile details are not mine instead it was my friend's profile details

Did this work before? N/A 

Chrome version: 56.0.2924.87  Channel: stable
OS Version: 
Flash Version: 

Isnt it the Browser's functionality to check the https links which is intended for user or to a particular machine..? Or isnt it a GMAIL's option to nullify the links details which has user related details .?

 

Comment 1 by vakh@chromium.org, Mar 1 2017

Status: WontFix (was: Unconfirmed)
To summarize: you got an email that contained a link which, when clicked, logged you in as the sender of the email instead as yourself.

Websites often send emails containing links that log the user in directly by embedding login information within the said link. If you click on such a link, you will be logged in as the user who received the email because that was the intent of that link.

Gmail can't remove such login information from the links for various reasons, including:
1. Gmail doesn't know whether the person 'A' who forwarded the email to 'B' intends 'B' to be able to login as 'A'.
2. There's no standard that defines how the login information is embedded in the link so it is impossible for Gmail to strip out the login information without completely breaking the link.

Marking this bug as WontFix since Chrome is working as expected.
Project Member

Comment 2 by sheriffbot@chromium.org, Jun 8 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment