New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 790732 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner:
Closed: Dec 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

User name field retaining e-mail addresses

Reported by raphruss...@gmail.com, Nov 30 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36

Steps to reproduce the problem:
1. Go to facebook.com in Google Chrome browser
2. type any letter in the user name field
3. random e-mail addresses (possibly from my outlook GAL) appear

What is the expected behavior?
My facebook username or nothing at all should populate.

What went wrong?
I apologize for the lack of details, but I tested this in Internet Explorer and Firefox and do not get these results. When I go to facebook.com and begin to type letters into the user name field, it populates the field with e-mail addresses that I presume it gets from my Outlook e-mails. I can't think of how else it is fetching this information. This is my personal PC, I do not allow other users to access or log into facebook from it. I noticed it when I was trying to remove my own user name from the auto-fill list. I am attaching a screenshot with the field auto-filling an e-mail address that does not belong to me. When I search Outlook, I notice that e-mail address does show up in one message to me as a CC. If you want any other information please let me know. If this is a Facebook issue, let me know and I will refer my report to them.

Did this work before? N/A 

Chrome version: 62.0.3202.94  Channel: stable
OS Version: 10.0
Flash Version: 

Please let me know if you are able to resolve this or would like more info from me, otherwise I will delete all these entries from the auto fill field. Also, I am using 2 Chrome extensions - Ghostery and Honey if that helps.
 
weird sign in issue.png
22.6 KB View Download

Comment 1 by raymes@chromium.org, Nov 30 2017

Cc: vasi...@chromium.org
Components: UI>Browser>Passwords Services>Sync
Labels: Security_Impact-Stable Security_Severity-High
Owner: ew...@chromium.org
Status: Assigned (was: Unconfirmed)
Are you logged into Chrome? 

ewald could you help triage? Also +vasilii for password manager.

Comment 2 by palmer@chromium.org, Nov 30 2017

Labels: Needs-Feedback
Do you mean outlook.live.com/outlook.com (web mail), or Outlook Web Access? Or do you mean the Outlook application for Windows, totally separate from the browser?

Comment 3 by ew...@chromium.org, Nov 30 2017

Cc: yiinho@chromium.org zea@chromium.org tschumann@chromium.org pav...@chromium.org
+Nicolas FYI
+Tim to see a typical cross-sync issue
+sync on-call

Sorry to hear about this confusing experience! Typically, when users see autofill data they don't recognize, it's because they accidentally synced another user's Chrome autofill data to their account on some shared machine.

In order to find out whether this is what's happening, we'll need a few things from you:

1. A screenshot of about:signin-internals
2. A screenshot of about:sync-internals
3. Permission for our on-call engineers to take a look at the data for your account on the server, to see how this erroneous autofill entry was synced to your account (i.e. from which device it was synced).

Could you please provide the above?

Thanks!
Hello all, I will try to answer all the questions.

I am not logged into Chrome, rarely ever do, and I am referring to the Outlook client installed on my PC, not Outlook online or OWA. I rarely ever use those in Chrome.

I will attach screenshots of the signin and sync internals. If these don't help us diagnose you can take a look at the back end, but since I have never signed in to Chrome, I don't see the point just yet.

Thanks for your help.
signinchrome.PNG
16.7 KB View Download
syncchrome.PNG
57.7 KB View Download
Cc: ma...@chromium.org
Components: -UI>Browser>Passwords -Services>Sync UI>Browser>Autofill
This is an autofill issue. On facebook.com Chrome Autofill offers to fill all the email addresses it knows about.
raphrussell@, you seem to know that email address. Is it possible that you typed it on any web form in Chrome?

Comment 6 by ew...@chromium.org, Dec 1 2017

Cc: ew...@chromium.org
Owner: ----
Status: Available (was: Assigned)
Removing myself as owner since this isn't a sync issue.
Project Member

Comment 7 by sheriffbot@chromium.org, Dec 1 2017

Labels: M-62
Project Member

Comment 8 by sheriffbot@chromium.org, Dec 1 2017

Labels: -Pri-2 Pri-1
Hello vasi, I only know about the e-mail because I searched it in my Outlook desktop client. I would never use someone else's e-mail in Chrome like that, and as I said, no one else logs into this PC. Is it possible that Chrome is pulling data from my Outlook somehow?

How does it know about the addresses other than the one's I've already punched in while browsing? How does it pull that info, maybe Outlook is leaking data to Chrome somehow, they do both tend to be open at the same time on my PC.

Let me know if you want more info and thanks.
Owner: vasi...@chromium.org
Status: Assigned (was: Available)
Assigning to vasilii to follow up on. Thanks!
Owner: ma...@chromium.org
Moving to mathp@ for triaging.
Project Member

Comment 12 by sheriffbot@chromium.org, Dec 7 2017

Labels: -M-62 M-63
Status: WontFix (was: Assigned)
Hi raphrussell@, there is a feature in Chrome that saves what you enter on some fields, to be able to propose it next time you enter data in an identical field.

The facebook field is <input name="email"...> and I'm guessing the one on Outlook is sharing the same name, hence Chrome trying to be helpful. 

I think there's no bug here, but I take note that you found it surprising.



Re #13: That explanation doesn't hold, insofar as #9 and #4 note that the user does not use Outlook Web Access in Chrome, only the Microsoft Office Outlook desktop client, which does not have any impact whatsoever on Chrome's autofill code.

Having said that, there's also no explanation that would result in the behavior described short of the user forgetting that they once used OWA or otherwise entered the email address in question in *some* web application.
OK thanks #14 I missed this. It remains that what I said is a likely explanation and should probably be investigated. The feature I described is called "Autocomplete" and if we could look in the Web Data database we could actually rule some things out.

@raphrussell: Are you comfortable enough looking into your internal database?

Here are the steps:
1) Locate your profile directory by going to chrome://version and looking for "Profile path"
2) Install SQLite browser for Windows: http://sqlitebrowser.org/
3) In SQLite browser, open the "<Profile Path>/Web Data" file, where <Profile Path> is what you identified in (1)
4) In browse data, look for the "autofill" table and see if the unexpected email is in there.




Note, you may have to shutdown Chrome for steps 3-4.
Hello, thanks for the ongoing help. I was able to open the web data file in SQL lite and when I browse the autofill table I do see some (but not all) of the addresses that will sometimes autofill in facebook login field. Here is a screenshot of a couple of the e-mails. I suppose it's possible I might have googled these at some point. And to clarify, I don't frequently use OWA but I have used it in the past, however, I don't believe I have entered these e-mails in any fields when browsing online. It wouldn't make sense for me to do that. They aren't my e-mail address. Let me know what you think.
chrome email.PNG
7.2 KB View Download
Thank you. Those values would have been saved as part of a form interaction (search, other form). If you'd like to delete those values, you can use the shift+delete shortcut when hovering over a given suggestion when it appears (a not very discoverable way, I'll admit). 


Project Member

Comment 19 by sheriffbot@chromium.org, Mar 16 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment