Security: Chrome Incognito Mode Privacy (on Android OS)
Reported by
muhammad...@gmail.com,
Apr 10 2018
|
||||||||
Issue descriptionVULNERABILITY DETAILS Chrome In-cognitive mode dose not provide privacy against visited websites such as www.olx.com, www.hotmail.com and many more. It dumps visited websites address in android logs. further steps for reproduction are listed in below section. VERSION Chrome (in-cognitive mode)[stable] Operating System: [Android] REPRODUCTION CASE Steps to reproduce: 1. start dumping android logs. (adb logcat > logs2.txt) 2. visit www.OLX.com or Microsoft Outlook in in-cognitive mode (on Google Chrome). 3. after visiting, close in-cognitive mode. and check android logs. 4. You will find visited web address (such as www.olx.com/xxx) in logs with "No preferred activity" logs. IMPACT: Any malicious application / use can access android logs (because no root access is needed), and may be dump your visited web address in-cognitive mode. further details may be share on request. Regards M Asim bangash.asim@hotmail.com
,
Apr 10 2018
Thanks for the report. I believe this had been reported before, but I can't find that bug, so we can just use this one. It is often difficult for us to prevent the OS from saving some information about the user's activity, but we do try to be defensive; and this particular case seems pretty solvable. For example, stripping or masking URLs in logs that come from the Incognito mode should not harm the usability of logs much, but would address this issue. It would be difficult to tell for each call of LOG() whether it pertains to Incognito or the regular mode. However, we can do e.g. the following: If an Incognito window is open, LOG() will run an additional check where the logged string is regex-matched for something that looks like an URL. If a URL is found, it is compared against those that are open in Incognito tabs. If it matches, we will strip it. rhalavati@: Adding this to your plate.
,
Apr 10 2018
No need for tight view restrictions.
,
Apr 11 2018
Thanks for consideration, Kindly acknowledge my work. Regards M Asim Bangash.asim@hotmail.com
,
Apr 12 2018
,
Apr 12 2018
How?
,
Apr 12 2018
The title does not exactly match, but the discussion in that bug has reached the conclusion to do a Chrome wide policy for notifications in incognito. Please see comment 26...
,
Apr 12 2018
Kindly, Refer comment 26.
,
Apr 13 2018
Sorry, but I don't get what you meant by last comment. Are you stating that this is a different problem and requires a separate bug?
,
Apr 13 2018
I was wrong, the two bugs are different. Moving back to assigned status.
,
Apr 14 2018
Ok, Thanks
,
Apr 16 2018
I think it would great if we could sanitize logs from incognito but I don't understand how another app would be able to get access to Chrome logs. Apps should not be able to read logs since Jelly Bean, which is also the minimum supported Android version of Chrome.
,
Apr 16 2018
,
Apr 16 2018
The article describes using ADB and eLogcat. Only eLogcat is an App and the article mentiones that it requires a rooted phone. What do you mean with "applications"? Do you mean Android apps or applications running on the device your phone is connected to?
,
Apr 16 2018
Android apps having root access,
,
Apr 16 2018
Apps on other device can acess via adb.
,
Apr 20 2018
,
Apr 24 2018
Hi Muhammad, I tried to reproduce the bug on Nexus 7, Chrome 66.0.3359.126, from Linux as follows: 1- I ran adb logcat > ~/Desktop/android_log.txt 2- Opened Chrome. 3- Went to BBC.COM in regular mode. 4- Opened incognito. 5- Went to www.olx.com in incognito. 6- Went to www.hotmail.com in incognito. 7- Closed Incognito. 8- Went to Aljazeera.com in regular mode. 9- Stopped ADB. I searched the log, BBC and Aljazeera were in the log, but olx, hotmail, and CNN were not. Do you have any suggestions on were I am wrong?
,
Apr 24 2018
Typo: Nexus 6P, Android 8.1
,
May 7 2018
I close the back based on lack of reproduciblity and feedback. Will open again if evidence was found. |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by carlosil@chromium.org
, Apr 10 2018Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Restrict-View-ChromePrivacy OS-Android Pri-3 Type-Bug
Summary: Security: Chrome Incognito Mode Privacy (on Android OS) (was: Security: Chrome In-cognitive Mode Privacy (on Android OS))