Issue metadata
Sign in to add a comment
|
Security: "Exit and Childlock" overwritten by clicking on a Chrome notification in Windows. Loads the user session without prompting for credentials
Reported by
riaan.fo...@gmail.com,
Jul 3 2017
|
||||||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS I had logged out of my Chrome session earlier in the day using the "Exit and Childlock Feature" so my wife could log in with her own account. When I got home there were YouTube notifications, generated by Chrome, waiting for me (Bottom right hand corner). My wife was still logged into her account on Chrome, but the notifications were from Youtube channels I follow. I signed her out using the "Exit and Childlock" feature, which got me back to the logon screen. I then accidentally clicked on one of the notifications, which then opened Chrome and loaded the youtube video - but also my previous tabs, which included Inbox. This all happened before I could actually use the User Logon window to sign in. I thought that it might have launched the tabs, but would prompt me to sign into the pages - but it didn't, just loaded my emails. In summary: YouTube notifications kept coming through Chrome, ignoring the fact that I had used the "Exit and Childlock" feature to sign out earlier in the day, and then proceeded to launch my previous session without prompting for credentials. VERSION Chrome Version: Version 59.0.3071.115 (Official Build) (64-bit) Stable Operating System: Windows 10 Version 1607 (OS Build 14393.1358) REPRODUCTION CASE Please see attached.
,
Jul 6 2017
Thanks, Eric. I'll close this one as a duplicate of 649088. |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by elawrence@chromium.org
, Jul 3 2017Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug