New issue
Advanced search Search tips

Issue 780574 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 766092
Owner:
Closed: Nov 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Info Leakage : UserName & Password is remembered by Chrome, even after the user has logged out of Chrome account

Reported by sumanta....@gmail.com, Nov 1 2017

Issue description



Please READ THIS FAQ before filing a bug: https://chromium.googlesource.com
/chromium/src/+/master/docs/security/faq.md

Please see the following link for instructions on filing security bugs:
https://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
When one logs out of Chrome, he is expecting all stored passwords to be removed/inaccessible to another person who is now having access to the computer/laptop.

Real life scenario : I was handing off my office laptop to IT and before handing over, logged off from my Google Accounts as well as my Chrome Account. However, when I tried to login to another site (without logging into Chrome account or Google account), the username and password show up.





VERSION
Chrome Version: 61.0.3163.100
Operating System: Windows 10 Enterprise version 1703 OS Build : 15063.632

REPRODUCTION CASE

Recreation steps :
1. Log in to chrome
2. go to a site (let's say site1.com) and click on remember me. This has the username & Pwd remembered by the Chrome browser
3. Log out of Chrome account
4. Try logging into "Site1.com" and Chrome will show the username and autofill the password

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace *with symbols*, registers,
exception record]
Client ID (if relevant): [see link above]

 
Components: UI>Browser>Passwords
Owner: vasi...@chromium.org
Hi vasilii@ - what's the expected behaviour here?
Mergedinto: 766092
Status: Duplicate (was: Unconfirmed)
Summary: Security: Info Leakage : UserName & Password is remembered by Chrome, even after the user has logged out of Chrome account (was: Security: Info Leakage : UserName & Password is remmebered by Chrome, even after the user has logged out of Chrome account)
This is working as intended, and duplicate of  Issue 766092 . When you sign out of Chrome, you are presented with the option to delete stored data.

To protect data stored in your operating system's user account, you must log out of the operating system. (Such protection is, of course, subject to the limitation that Administrative users are typically able to recover data from the user accounts they manage).
Project Member

Comment 3 by sheriffbot@chromium.org, Feb 14 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment