New issue
Advanced search Search tips

Issue 808820 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 781138
Owner: ----
Closed: Feb 2018
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Even after changing password, Chrome browser allows to access secure applications

Reported by sharma.a...@gmail.com, Feb 3 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36

Steps to reproduce the problem:
Steps to recreate -
1. Log in in to chrome browser with google account.
2. Let it remember your few passwords.
3. Now change your google account password from other system.
4. Again come to the system in #1 and try to access applications using chrome. 

What is the expected behavior?
It should shpow the message to log in again but MUST NOT let me open any application rememebered here. I should not even show my history and bookmarks.

What went wrong?

Actual Result -
It shows message that "sign-in to browser couldn't be done and asks to login again", But the applications remembered on this browser can still be opened except G-Mail. In attached screenshot I could open the Facebook and outlook email accounts successfully. Alongwith this, it shows my bookmarks and history.

Repercussion -
SO in case, if by mistake, i login to Chrome browser in any public system. Even after I change my password, Anyone can access my all accounts, can do all fruads. It is the biggest threat.

Did this work before? N/A 

Chrome version: 63.0.3239.132  Channel: n/a
OS Version: 10.0
Flash Version:
 
ChromeBug.jpg
173 KB View Download
Mergedinto: 781138
Status: Duplicate (was: Unconfirmed)
Changing your Google account password does not impact data stored on other computers or browser instances. It only impact login to Google accounts and services.
Project Member

Comment 2 by sheriffbot@chromium.org, May 13 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment