New issue
Advanced search Search tips

Issue 738934 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 649088
Owner: ----
Closed: Jul 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Security: "Exit and Childlock" overwritten by clicking on a Chrome notification in Windows. Loads the user session without prompting for credentials

Reported by riaan.fo...@gmail.com, Jul 3 2017

Issue description

VULNERABILITY DETAILS
I had logged out of my Chrome session earlier in the day using the "Exit and Childlock Feature" so my wife could log in with her own account. When I got home there were YouTube notifications, generated by Chrome, waiting for me (Bottom right hand corner). My wife was still logged into her account on Chrome, but the notifications were from Youtube channels I follow. I signed her out using the "Exit and Childlock" feature, which got me back to the logon screen. I then accidentally clicked on one of the notifications, which then opened Chrome and loaded the youtube video - but also my previous tabs, which included Inbox. This all happened before I could actually use the User Logon window to sign in. 

I thought that it might have launched the tabs, but would prompt me to sign into the pages - but it didn't, just loaded my emails.

In summary: YouTube notifications kept coming through Chrome, ignoring the fact that I had used the "Exit and Childlock" feature to sign out earlier in the day, and then proceeded to launch my previous session without prompting for credentials.

VERSION
Chrome Version: Version 59.0.3071.115 (Official Build) (64-bit) Stable
Operating System: Windows 10 Version 1607 (OS Build 14393.1358)

REPRODUCTION CASE
Please see attached.
 
2017-07-03 19_08_32-(44) Dragonball FighterZ Brings the Anime to Life - YouTube.png
960 KB View Download
Components: Services>SupervisedUser UI>Browser>Profiles
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
I believe this is the same as Issue 649088.
Mergedinto: 649088
Status: Duplicate (was: Unconfirmed)
Thanks, Eric. I'll close this one as a duplicate of 649088.

Sign in to add a comment