New issue
Advanced search Search tips

Issue 839231 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 126398
Owner: ----
Closed: May 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Access to user-saved password doesn't require root authentication

Reported by mendickx...@gmail.com, May 3 2018

Issue description

VULNERABILITY DETAILS
If I want to see my password saved in the Chrome's manage passwords setting, I need to know the root authentication of the computer, like this one.
 
But I found a way to see my password and not need the root authentication.
Step 1: I login my AWS service, The chrome will fill the username and password automatically. Here the password is still shown as ********
 
Step 2: Open the Secret Server in the AWS and store a new secret. The username and password will fill in as the credentials for RDS database. I can also select the username and password from the saved password. 
 

Step 3: I clicked the show password checkbox, then I can see my password. There is no requirement to login by the root authentication of the computer
 
So, I think this is a security bug in the Chrome’s save password function, it should be request a root authentication if I click the show password.

Step 4: I logout the AWS, and use the federation login to the Amazon, and I repeat the Step 2 and Step 3, I can also select the item saved in the chrome save passwords component. And I also can see the password not to login by the root authentication of the computer.
 

The whole team shares the team account, so if another people in the team to use my computer, he will get my password for my personal account. So, I think this is a critical security issue and need to confirm it.

VERSION
Chrome Version: 65.0.3325.181 (Official Build) (64-bit)
Operating System: Windows 7 Enterprise, Service Pack 1
 
 
REPRODUCTION CASE
See the VULNERABILITY DETAILS

Please contact with me by the mailbox: mendick2000@163.com
 
Google Chrome VULNERABILITY DETAILS.docx
437 KB Download
Components: UI>Browser>Passwords
Mergedinto: 126398
Status: Duplicate (was: Unconfirmed)
Please see https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#What-about-unmasking-of-passwords-with-the-developer-tools

and

https://textslashplain.com/2017/10/16/stealing-your-own-password-is-not-a-vulnerability/

Sharing a single PC user-account is fundamentally non-secure, even when you do not store passwords.
Summary: Security: Access to user-saved password doesn't require root authentication (was: Security: Access the user saved password in the chrome not need the room authentication)
Project Member

Comment 3 by sheriffbot@chromium.org, Aug 10

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment