New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 750499 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: After logging into Chrome, local passwords sync to my sync'd profile

Reported by ags.od...@gmail.com, Jul 30 2017

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://www.chromium.org/Home
/chromium-security/security-faq

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.

i logged into google on a friends laptop so i could pick up my browsing history and bookmarks and logged out after using it. to my surprise when i log into google from any computer it has merged all my friends passwords and mine. In other words both she and i and another user (who she bought the laptop from) can all see each other's saved passwords. this means if i want i can see both her login usernames and passwords for all her social media, email and other accoutns nad vice versa. I have manually deleted a number in google settings but have screenshotted those that remain. this is a serious security flaw and is the third time i have noted this behaviour in the past year.  

VERSION
Chrome Version:  59.0.3071.115 stable 
Operating System: Windows 10 Home 64 bit build 15063.483

REPRODUCTION CASE
please see several screenshots and not the number of occasions where the usernae redfern.tom@gmail.com and fran wilkinson appears. these have somehow come into my gmail account becuase i logged into google through chrome on fran wilkinson's computer.

 
screenshots.zip
1.8 MB Download
Components: UI>Browser>Profiles Services>Sync
Summary: Security: After logging into Chrome, local passwords sync to my sync'd profile (was: Security: whe logging into google from a friend's laptop)
Please be specific about what you clicked when you "logged into google"?

When you log into *Chrome* (as in the attached screenshot), this syncs the data from the current local Profile (including credentials) to the selected Google account.
Screen Shot 2017-07-30 at 1.13.44 PM.png
44.8 KB View Download

Comment 2 by vakh@chromium.org, Jul 31 2017

Labels: Needs-Feedback
Status: WontFix (was: Unconfirmed)
Closing due to lack of feedback; this does appear to be working as intended.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 14 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment