New issue
Advanced search Search tips

Issue 798620 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Bypass password to get to password manager in chrome.

Reported by mattstor...@gmail.com, Jan 3 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0

Steps to reproduce the problem:
1. Go to a website with saved password. In my case it was https://credit.kohls.com/eCustService/
2. Click the key on the right of the URL
3. Click 'Manage Passwords'

What is the expected behavior?
When you go to passwords.google.com you have to re-enter your google password to see your saved passwords. When you click manage passwords from the key icon you don't have to re-enter your google password.

What went wrong?
You don't have to enter a password to get to your saved passwords in passwords.google.com. Instead you can reach them through the manage passwords URL from the key icon.

Did this work before? N/A 

Chrome version: Version 63.0.3239.108 (Official Build) (64-bit)  Channel: stable
OS Version: 7
Flash Version: Shockwave Flash 28.0 r0

The person would need access to the computer and the login to the computer and would also need to have the google account all ready logged in.
 
Components: UI>Browser>Passwords
Status: WontFix (was: Unconfirmed)
Thank you for the report, this does not look like a security issue though.

passwords.google.com asks for your google password because it can be accessed by anyone.

The chrome password manager does not require your google password because to access it you must be on the same machine. 

Attacks that require being on the same machine are outside of Chrome's threat model (https://dev.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-).
Project Member

Comment 2 by sheriffbot@chromium.org, Apr 11 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment