New issue
Advanced search Search tips

Issue 743582 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 656424
Owner: ----
Closed: Jul 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Supporting Powerwash from non-owner login

Reported by shreyasj...@gmail.com, Jul 15 2017

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://www.chromium.org/Home
/chromium-security/security-faq

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.
As a non owner login for Chrome Book, I was able to Powerwash the Chromebook. 

VERSION
Chrome Version: Version 59.0.3071.113 stable
Operating System: 
Google Chrome OS
Version 59.0.3071.113 stable
Platform 9460.67.0 (Official Build) stable-channel cave
Firmware Google_Cave.7820.288.0

REPRODUCTION CASE

I was able to reset the Chromebook using non-owner credentials and wipe the Chromebook clean. Even though this appears to be a handy feature supported by Chrome OS but its a security bug which can wipe out the owner's information.

So any important information stored by owner is lost forever and the new owner can use the Chromebook.

Powerwash should be applicable only to owner login similar to option of changing the Channel from Stable to Beta.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Not applicable.

 
Components: Enterprise
Labels: OS-Chrome
Mergedinto: 656424
Status: Duplicate (was: Unconfirmed)
Users with physical access are inherently powerful: https://dev.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-
Project Member

Comment 2 by sheriffbot@chromium.org, Oct 22 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment