New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 832194 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Behavior of password synchronization via Google account is unexpected

Reported by alluriak...@gmail.com, Apr 12 2018

Issue description



Hi Google
I think i might have found a huge bug in the way passwords are saved on chrome in your google account
Here is how you can reproduce it:
1.Go to any website
2.Log into it and save your password
3.That password clearly appears in your manage passwords list of your google account
4.Now if I log out of that account and also delete that account from that system I am still able to get access to that password which I saved.

Also the other way is that if I have a password saved on my google account and I log into a new compter with that account,do my stuff,and log out of my account,my password is still there

Scenario:
Victim goes to a public computer center and logs into his account
He does all his work and later deletes his account from that computer
Attacker uses that computer after him and has access to all his saved passwords and can easily log into the victim's accounts.

Note
I have personally tried it on 3 different computers and i was able to get easy access.Its like once someone logs into a computer with their gooogle account all of their saved passwords are comprimised.

Please look into this matter ASAP
Thank you


PS-If any of my mentioned statements are not clear please contact me ASAP.This I believe is a HUGE flaw and must be corrected

 
Signing out of Chrome only deletes previously-synced data (including passwords) if you check the box.

https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Signing-out-of-Chrome-does-not-delete-previously_synced-data
Signout.png
17.9 KB View Download
Status: WontFix (was: Unconfirmed)
Closing this one since this is looks like this is WAI.
In the first scenario, if you delete your stored password from the sync'd local profile, the deletion will eventually sync to the Google account and the Google account will delete the stored password as well.

The second scenario is dupe of  Issue 792967 .
Components: UI>Browser>Passwords Services>Sync
Summary: Behavior of password synchronization via Google account is unexpected (was: Security_Severity 100%)
Project Member

Comment 6 by sheriffbot@chromium.org, Jul 21

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment