New issue
Advanced search Search tips

Issue 801004 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2018
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: loophole found

Reported by dovberbr...@gmail.com, Jan 11 2018

Issue description

Hi there.
I wish to report a very big loophole I found in Google's security.
It involves using Chrome remote desktop, and also applied to cloud print (and maybe some other Google products).

Here's what I've been able to do:

Use someone's computer for a few minutes, (can be in a lounge, Library, someone's office Etc), I then log into Chrome (add person, then log-in). Then go to the persons Chrome remote desktop app, press disable (if he had it enabled already), then I press enable, thus putting the computer under MY account's Authority.
I can then click to remove my profile from that person's computer, leaving no trace that I ever even logged in. 
and here's the massive loophole: my account is still the owner over that person's Chrome remote desktop app. Yes, even after I logged out and remove myself from chrome!
So I can still access the computer whenever I want (as long as he doesn't disable connections it and then re-enable it under his account).
This same bug, also applies to Google Cloud Print, that whichever account is the one to add the printer, stays the owner, even when logged out!
 
Status: WontFix (was: Unconfirmed)
Thanks for the report. Since you have physical access to another person's computer, you can do whatever you like to their machine. You can copy their entire hard drive and install whatever programs you like, or install a VNC program for another way to permanently have remote access. This is why physically local attacks are not part of Chrome's threat model: there is very little we can do to protect you if an attacker has unfettered access to your machine.

See https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Why-arent-physically_local-attacks-in-Chromes-threat-model for more details.
Project Member

Comment 2 by sheriffbot@chromium.org, Apr 19 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment