New issue
Advanced search Search tips

Issue 825653 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 825651
Owner: ----
Closed: Mar 2018
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Passwords leaked without system user password prompt

Reported by florin1c...@gmail.com, Mar 25 2018

Issue description

VULNERABILITY DETAILS

If you try to manage or see your passwords stored in Chrome you will be prompted with a toast asking for the Windows User password, which makes sense since you do not want anybody to be able to get all your passwords in bulk.

I recently started to play with the Brave Browser and to my surprise it has a functionality where it can import all your passwords from Chrome. It works well and after executing this password import you have access to absolutely all the passwords stored in chrome, without having to input any passwords in Brave or even have a Brave account. The Brave browser is Open Source with code on Github so I am assuming that it would not be difficult some day for someone to send you a picture with embedded code and execute the Brave browser code in order to get your passwords.

VERSION
Chrome Version: Version 65.0.3325.181 (Official Build) (64-bit)
Operating System: Windows 10 PRO

 

Comment 1 by cthomp@chromium.org, Mar 26 2018

Mergedinto: 825651
Status: Duplicate (was: Unconfirmed)
Project Member

Comment 2 by sheriffbot@chromium.org, Jul 3

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment