New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 761603 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 746136
Owner: ----
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Stealing passwords using Sync

Reported by seven.sr...@gmail.com, Sep 2 2017

Issue description

Hi Team,

When I save a Username and Password on another computer without logging into the Brower and later when I login it's importing all the usernames and saved in that computer into my account.

I think someone can steal all the usernames and password using this simple method.

Reproduce the issue:


1) Connect to Computer A.
2) Open some login page and Save Username and Password.
3) Login into Google Chrome.
4) Give some 10 Mins to get Sync.
5) You will see that the Login Username and Password which are saved while not logged in into the Google Chrome are imported into your account.
6) You can login into any other computer and you will get the Usernames and passwords that are previously saved in another computer.

Thanks,
Srikanth

 
Components: UI>Browser>Passwords Services>Sync
Mergedinto: 746136
Status: Duplicate (was: Unconfirmed)
Summary: Security: Stealing passwords using Sync (was: Security: Importing all the Logins Information)
Yes, when given unrestricted physical access to a user's PC, there are numerous mechanisms for obtaining the user's stored passwords as discussed here: https://dev.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-

In this version, the attacker uses Sync to egress the victim's passwords to their own account in the cloud, then simply views the passwords on a different computer at their leisure.
Project Member

Comment 2 by sheriffbot@chromium.org, Dec 10 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment