New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 789212 link

Starred by 2 users

Issue metadata

Status: Unconfirmed
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 3
Type: Bug


Show other hotlists

Hotlists containing this issue:
Hotlist-1


Sign in to add a comment

Corina--android malware apps syncing to every account/ Users logging into cb

Reported by dahlia98...@gmail.com, Nov 28 2017

Issue description

Platform
10134.0.0 (Official Build) dev-channel edgar
Firmware
Google_Edgar.7287.167.71
Channel
Currently on dev
ARC Version
4453597
Blink
537.36 (@)
V8
6.4.307
User Agent
Mozilla/5.0 (X11; CrOS x86_64 10134.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3270.0 Safari/537.36
Command Line
/opt/google/chrome/chrome --ppapi-flash-path=/opt/google/chrome/pepper/libpepflashplayer.so --ppapi-flash-version=27.0.0.187 --ui-prioritize-in-gpu-process --use-gl=egl --enable-native-gpu-memory-buffers --gpu-sandbox-failures-fatal=yes --enable-logging --log-level=1 --use-cras --enable-wayland-server --user-data-dir=/home/chronos --max-unused-resource-memory-usage-percentage=5 --login-profile=user --has-chromeos-keyboard --default-wallpaper-large=/usr/share/chromeos-assets/wallpaper/oem_large.jpg --default-wallpaper-small=/usr/share/chromeos-assets/wallpaper/oem_small.jpg --default-wallpaper-is-oem --guest-wallpaper-large=/usr/share/chromeos-assets/wallpaper/guest_large.jpg --guest-wallpaper-small=/usr/share/chromeos-assets/wallpaper/guest_small.jpg --enable-consumer-kiosk --arc-availability=officially-supported --enterprise-enrollment-initial-modulus=15 --enterprise-enrollment-modulus-limit=19 --login-manager --first-exec-after-boot --vmodule=*arc/*=1,tablet_power_button_controller=1,*chromeos/login/*=1,auto_enrollment_controller=1,*plugin*=2,*zygote*=1,*/ui/ozone/*=1,*/ui/display/manager/chromeos/*=1,*night_light*=1,power_button_observer=2,webui_login_view=2,lock_state_controller=2,webui_screen_locker=2,screen_locker=2
Build Date
Thursday, November 16, 2017


What steps will reproduce the problem?
Normal Ops.
This is a brand new chromebook using a newly created email.  I have multiple logs already in the system for the same issues. This email has enhanced protection. The problem is I have multiple malicious extensions I cannot remove or access that are downloading to every single account I have as well as spreading to my family and friends, and multiple strangers are able to log into every account I have, Note I have only one account on each chromebook.  I do not have accounts signed in on multiple places.

 The ongoing issue is (I believe) goes back to galaxy 4 and stagefright mms vulnerability and multiple users encrypting malware apps and adding approx 20 phones to my 2 primary emails under samsung.com.  The malicious apps and settings ended up downloading from samsung to verizon, after my 3rd phone I left verizon and android. 

Up until a few months ago, the only issue I had noticed was multiple open sessions, though I did not understand the significance at the time.  I made the mistake of logging into a tablet with a "real" email and then all these old galaxy 4,5,6 malware apps downloaded to all my chromebooks 6 months ago (On models they should not have been able to operate on)  

Though I have attempted to lock everything down tight on all the other chromebooks---  This one powerwashes!!  ;)  the circle goes around about 33 times vs .5 a revolution for the other 3 cbs I have.

I have have also elected to sync everything on this box to google servers, in case this is helpful to you..  I have gone to google play and of the visible apps I could find, updated them hopefully to current.  But not every app listed on google play because they are fake.  And I see that google play wants permission to download apps and their data to google drive.  WHERE CAN I FIND THESE APPS on GOOGLE DRIVE.  

PLEASE MAKE A tool to access my DRIVE.  I think that is reasonable to an enhanced protected user account????   I realize you say Google drive is private and you don't have access to it, but I had trolls crawling all over mine- So it makes ZERO sense you would be blind to what people are loading on your users google drive, and you don't notify users when they are managed, and you don't actively audit everyone's google drive for malware.  My android hackers had unfettered access to EVERYTHING for months and months. Please give me a digital scalpel so I can remove this cancer.  

If I can give you anything more at all please let me know.

Thank you very much.  I appreciate your assistance. 

I believe this chromebook thinks it's managed, which shouldn't be possible-- who do I check to find out the source?  I also need to find out which aliases you have identified for me....  My son for example is somehow identified as an alias for my account, and the hackers added his account to icloud and MSN.   I can't fight this unless I know where all the accounts are.   I hope these people are locked out and cannot send email now as me, but they used to be able to and the damage is done.  I just need to find it and remove it.  One example is google my maps.  This dumb apps download on every chromebook and has 6 total users.

What is the expected result?
New Chromebook, Protected gmail account= Pure account.  

What happens instead?
Malware apps loaded at login, multiple people logging in constantly from alternate locations---  under my own IP??

Also I noticed it says this device isn't certified, which according to what I read is due to apps installed on this device that google isn't certain about.  It's not the manufacturer my friends, these are all the malware apps from galaxy 4,5,6 and stagefright and loaded on my google drive and syncing because of a the gsuites people have signed my up for and it all syncs to chromebook.   

Suggestion---  In an account as messed up as mine are, I cannot get a concise accounting of installed apps.

-----This initial submission failed, I might have a problem sending files to you.  I will try again.  My files app is maleware (I think and since I reloaded google drive I think the files app is broken).  So please ignore the order listed below, I will just try to reload again

1. debug
2  System crash
3  all the weird apps
4 google play w/ toggle to show installed apps
5  Scrollllllll  to find one I installed last night.  Would be nice to actually sort on installed column.
6  hackers logging into my account last night
7  on googleplay, it said no apps installed initially.  I searched out the ones I could (11 total ) and installed in hopes of correcting some of this the malware.

I hope this helps.  Please help me find the source of this.  I believe there are more gsuite accounts effecting me--  How else could this go from even a brand account no matter what I do?   

P.S. Advanced account protection will NOT PROTECT me from GOOGLE MALWARE.  I need access to the root of my google drive and a list of all my aliases PLEASE



 
debug-logs_20171128-093245
1.1 MB View Download
Screenshot 2017-11-28 at 12.47.04 AM.png
1.4 MB View Download
Screenshot 2017-11-28 at 9.33.52 AM.png
816 KB View Download
Screenshot 2017-11-28 at 10.12.28 AM.png
1.3 MB View Download
Screenshot 2017-11-28 at 10.17.43 AM.png
140 KB View Download
Screenshot 2017-11-28 at 10.17.59 AM.png
134 KB View Download
Screenshot 2017-11-28 at 10.33.40 AM.png
139 KB View Download
Labels: Needs-Milestone
Cc: vamshi.k...@techmahindra.com
Labels: Triaged-ET OS-Chrome
This issue seems to be related to OS-Chrome, hence adding OS label.
Dear google friends.  I have installed your recent updated to dev, and I see you disabled instant tethering which is good.  I have been researching the flags and it seems to me that multidevice is the setting that brought my chromebooks down to their knees.  Again,  this goes back to my first galaxy 4, stage fright, a cracked kernel for 4+ years as I tried to fight this in the dark on galaxy 4,5,6,7.  As it seems chromebook is merging chrome apps and google play what   should people that were victims of stage fright/ samsung knox and it's multiple malware variants do? I had 20 People register their phones under my 2 main accounts and turning on multidevice in July or so propagated all that android malware to every single account I am associate with on my chromebooks and and google accounts including my kids and friends and family, even just people I helped even if I am only a recovery email.  The chromebook that runs c.w is not even using a real version of chrome. it's a stand alone version and the chromebook wont powerwash.   I have signed up for google enhanced protection, and I have stated numerous times I give you permission to do whatever you need to stop this.  I have NO PRIVACY NOW.  I have people logging in to whatever new email account I make because your system associates me as an alias and it's a free for all.   Please help me get off this crazy train.    Please stop these freaks they are stealing from me.   They are stealing my credit cards, I'm afraid to pay my bills online.  I know this is not fun for you to read but it's ruining my life.  And I have a son that is 17 and wants to go to college and he gets almost straight A's.  I have to do right by my boy, but what do I do if I can't WORK? PLEASE I beg you to help me.  I am sorry but I can't take this much longer, why can't you fix this?  I think this is all on my google drive.  I will do what ever you need.   You cannot imagine how horrible my life has been.  I worked in a corp environment for 20 years, and am sucked into a nightmare for the last 5. I can do nothing but beg.  But understand helping me fix this, will make all your clients safer.  I have people accessing my email and google drive at least every hour when I log in no matter what account I am on.  I will do what ever I can to help you.  Please help me,  they even have hacked all my kids and at least one of my sons friends and I don't know how far this has spread.  I do know it's not just me.  I am deleting accounts as I find them.--  please help me

Comment 4 by vsu...@chromium.org, Jan 16 2018

Components: Security
Dear Friends.  Can I do anything to help?  How do I know when they are all gone?  How do I totally stop all the chrome devices I have from synching?  Because it's bizarre that another chromebook log said that mrscleannw was syncing to other computers-  And unless thats because of my phone number being in the account, will removing my mobile stop this?  I am in advanced privavcy protections with yubikey and feitan.    I have an android tablet I no longer use, and no longer have an android phone.  I really need all my google accounts to stay separate. I can ship you this chromebook if you wish to see where the bad apps are coming from.  Please let me help.  If this current chromebook needs tossed out, just say it and its gone.  I just need direction.  I will follow all your instructions to the T.  I am lost please help me.

Sign in to add a comment