New issue
Advanced search Search tips

Issue 766145 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner: ----
Closed: Sep 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Master Password Autofill

Reported by the.timo...@gmail.com, Sep 18 2017

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://chromium.googlesource.com
/chromium/src/+/master/docs/security/faq.md

Please see the following link for instructions on filing security bugs:
https://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Google Smart Lock is effectively a password safe/manager.  However, I believe it has a flaw in that a User can inadvertently allow login verification to be bypassed.  FOr example, on my phone I had forgotten a login so I went to Chrome->Settings->Saved Passwords.  To view/change passwords, I had to visit passwords.google.com.  
On arriving at the login page I was required to enter my password to "Verify my identity" but was immediately offered the opportunity to autofill my password.  This effectively bypasses the need to enter a password giving access to multiple logins.

passwords.google.com should require a user to manually enter a password. 

VERSION
Chrome Version: All
Operating System: All

REPRODUCTION CASE
Visit passwords.google.com to view Passwords.  On entering the password box, the opportunity to autofill will be offered.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace, registers, exception record]
Client ID (if relevant): [see link above]

 
Revise Chrome version to 60.0.3112.116 on Android until confirmed on PC.
Components: UI>Browser>Passwords
Per Issue 747828, this was fixed in Chrome 61.
Thanks.  Not seeing that update on my device at the moment but see it has been updated on the Play Store.  Will hopefully come through in the next few days.  PC was also same but is currently updating to 61.
Many thanks.

Comment 4 by mea...@chromium.org, Sep 18 2017

Mergedinto: 747828
Status: Duplicate (was: Unconfirmed)
the.timo1972: Please let us know if you still see this problem after upgrading to 61. I'll close the bug for now. Thanks.
Will do.  Still waiting for the update to come through. 
Project Member

Comment 6 by sheriffbot@chromium.org, Dec 26 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Follow-up. Chrome at V63 on Android. Issue no longer present. 

Sign in to add a comment