Issue metadata
Sign in to add a comment
|
User name field retaining e-mail addresses
Reported by
raphruss...@gmail.com,
Nov 30 2017
|
||||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36 Steps to reproduce the problem: 1. Go to facebook.com in Google Chrome browser 2. type any letter in the user name field 3. random e-mail addresses (possibly from my outlook GAL) appear What is the expected behavior? My facebook username or nothing at all should populate. What went wrong? I apologize for the lack of details, but I tested this in Internet Explorer and Firefox and do not get these results. When I go to facebook.com and begin to type letters into the user name field, it populates the field with e-mail addresses that I presume it gets from my Outlook e-mails. I can't think of how else it is fetching this information. This is my personal PC, I do not allow other users to access or log into facebook from it. I noticed it when I was trying to remove my own user name from the auto-fill list. I am attaching a screenshot with the field auto-filling an e-mail address that does not belong to me. When I search Outlook, I notice that e-mail address does show up in one message to me as a CC. If you want any other information please let me know. If this is a Facebook issue, let me know and I will refer my report to them. Did this work before? N/A Chrome version: 62.0.3202.94 Channel: stable OS Version: 10.0 Flash Version: Please let me know if you are able to resolve this or would like more info from me, otherwise I will delete all these entries from the auto fill field. Also, I am using 2 Chrome extensions - Ghostery and Honey if that helps.
,
Nov 30 2017
Do you mean outlook.live.com/outlook.com (web mail), or Outlook Web Access? Or do you mean the Outlook application for Windows, totally separate from the browser?
,
Nov 30 2017
+Nicolas FYI +Tim to see a typical cross-sync issue +sync on-call Sorry to hear about this confusing experience! Typically, when users see autofill data they don't recognize, it's because they accidentally synced another user's Chrome autofill data to their account on some shared machine. In order to find out whether this is what's happening, we'll need a few things from you: 1. A screenshot of about:signin-internals 2. A screenshot of about:sync-internals 3. Permission for our on-call engineers to take a look at the data for your account on the server, to see how this erroneous autofill entry was synced to your account (i.e. from which device it was synced). Could you please provide the above? Thanks!
,
Dec 1 2017
Hello all, I will try to answer all the questions. I am not logged into Chrome, rarely ever do, and I am referring to the Outlook client installed on my PC, not Outlook online or OWA. I rarely ever use those in Chrome. I will attach screenshots of the signin and sync internals. If these don't help us diagnose you can take a look at the back end, but since I have never signed in to Chrome, I don't see the point just yet. Thanks for your help.
,
Dec 1 2017
This is an autofill issue. On facebook.com Chrome Autofill offers to fill all the email addresses it knows about. raphrussell@, you seem to know that email address. Is it possible that you typed it on any web form in Chrome?
,
Dec 1 2017
Removing myself as owner since this isn't a sync issue.
,
Dec 1 2017
,
Dec 1 2017
,
Dec 1 2017
Hello vasi, I only know about the e-mail because I searched it in my Outlook desktop client. I would never use someone else's e-mail in Chrome like that, and as I said, no one else logs into this PC. Is it possible that Chrome is pulling data from my Outlook somehow? How does it know about the addresses other than the one's I've already punched in while browsing? How does it pull that info, maybe Outlook is leaking data to Chrome somehow, they do both tend to be open at the same time on my PC. Let me know if you want more info and thanks.
,
Dec 4 2017
Assigning to vasilii to follow up on. Thanks!
,
Dec 4 2017
Moving to mathp@ for triaging.
,
Dec 7 2017
,
Dec 7 2017
Hi raphrussell@, there is a feature in Chrome that saves what you enter on some fields, to be able to propose it next time you enter data in an identical field. The facebook field is <input name="email"...> and I'm guessing the one on Outlook is sharing the same name, hence Chrome trying to be helpful. I think there's no bug here, but I take note that you found it surprising.
,
Dec 7 2017
Re #13: That explanation doesn't hold, insofar as #9 and #4 note that the user does not use Outlook Web Access in Chrome, only the Microsoft Office Outlook desktop client, which does not have any impact whatsoever on Chrome's autofill code. Having said that, there's also no explanation that would result in the behavior described short of the user forgetting that they once used OWA or otherwise entered the email address in question in *some* web application.
,
Dec 7 2017
OK thanks #14 I missed this. It remains that what I said is a likely explanation and should probably be investigated. The feature I described is called "Autocomplete" and if we could look in the Web Data database we could actually rule some things out. @raphrussell: Are you comfortable enough looking into your internal database? Here are the steps: 1) Locate your profile directory by going to chrome://version and looking for "Profile path" 2) Install SQLite browser for Windows: http://sqlitebrowser.org/ 3) In SQLite browser, open the "<Profile Path>/Web Data" file, where <Profile Path> is what you identified in (1) 4) In browse data, look for the "autofill" table and see if the unexpected email is in there.
,
Dec 7 2017
Note, you may have to shutdown Chrome for steps 3-4.
,
Dec 7 2017
Hello, thanks for the ongoing help. I was able to open the web data file in SQL lite and when I browse the autofill table I do see some (but not all) of the addresses that will sometimes autofill in facebook login field. Here is a screenshot of a couple of the e-mails. I suppose it's possible I might have googled these at some point. And to clarify, I don't frequently use OWA but I have used it in the past, however, I don't believe I have entered these e-mails in any fields when browsing online. It wouldn't make sense for me to do that. They aren't my e-mail address. Let me know what you think.
,
Dec 8 2017
Thank you. Those values would have been saved as part of a form interaction (search, other form). If you'd like to delete those values, you can use the shift+delete shortcut when hovering over a given suggestion when it appears (a not very discoverable way, I'll admit).
,
Mar 16 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by raymes@chromium.org
, Nov 30 2017Components: UI>Browser>Passwords Services>Sync
Labels: Security_Impact-Stable Security_Severity-High
Owner: ew...@chromium.org
Status: Assigned (was: Unconfirmed)