New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 839311 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner:
Closed: Jun 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: 2
Type: ----

Blocked on:
issue 837798



Sign in to add a comment

Private information can be easily obtained even after signing out of certain secure services through Chrome Thumbnails

Reported by dhruvjha...@gmail.com, May 3 2018

Issue description

So here's my first try at a bug report. I tried to stick to the format provided because at school that's where most of the marks lie ^.^

I have been a chrome user since the beginning of time, and it has proven to be one of the most secure browsers ever. But for a long time now the fact that i can see a snapshot of which ever site I frequently visit in the new tab 'quick launch' (those 8 thumbnails) has bothered me.


PRIVACY ISSUE

Surely I can remove the thumbnails but that isn't my concern here. To explain what I have to say I would like you to picture this scenario in your mind. The user is logged into chrome and uses it for his personal reasons, for this situation lets say he uses a reputed and end to end encrypted service like whats app web for communicating with his peers some information which he wouldn't like others to know.

After using WhatsApp Web he logs out of it to prevent others from seeing what he was up-to, but here's the catch, chrome takes a snap of the site when he was logged in and displays it in one of those 8 thumbnails.

And to my surprise the image is very easy to obtain and in spite of it being quite small a lot of details are legible, all of this even though that person logged out of his account in WhatsApp web. And since that image is that easily accessible some other person with hostile intentions would obtain this data with ease making me raise an eyebrow on privacy protection.

WhatsApp web(or any other secure service) or sharing some secret information isn't my reason of worry but its the fact that in spite of logging out of a secure site crucial photographic data can be easily obtained for the same.

VERSION:
Chrome Version: [Version 66.0.3359.139 (Official Build)] + [stable]
Operating System: [Windows 10, 10.0.16299]

REPRODUCTION STEPS
1. Get into a secure service and use it frequently till it appears in the 8 thumbnail place in the new tab, Or just look for one because there probably might be one which you use.

2. Click the quick launch thumbnail which you meets the requirements of step 1.

3. Log out of that service and return to your new tab.

4. locate that same thumbnail and notice that it still has a snapshot of the website when you were logged in.

5. Right click on it and click on 'inspect element' when that context menu opens

6. Dev tools would open up and the source link of concern would be highlighted in blue.


7. Double click on the blue highlight to select only the source link

8. Paste the source link in a new tab

9. Bon Apatite, on your screen you should see a small picture of the website you had logged out of and upon zooming(ctrl & +) in you might be able to make out some things that you wouldn't want others to see.

That's about it. I haven't heard anyone report this before so I hope I'm the first. Almost forgot to introduce myself... I'm Dhruv and I'm 15. The only reason I entered was because I read an article on some dude striking it rich after reporting a bug in a Google Pixel device, If I do happen to get anything from this It would be spent on making that computer I've always wanted so don't be afraid to be generous :-P. Alrighty! That's the end of it. Please do get back to me if any other 'documentation' is required. Cheers! 
 
Nevermind, just saw someone else report something similar... *sigh*
Cc: yyushkina@chromium.org
Components: UI>Browser>NewTabPage UI>Browser>ContentSuggestions
Labels: -Pri-3 OS-Chrome OS-Linux OS-Mac OS-Windows Pri-2
Thanks for the report. We have reduced the resolution of the thumbnails in the past to mitigate the privacy concerns, but this indeed keeps coming up.

+yyushkina@ who, I believe, has plans to address this.
Indeed. We're addressing this by M69 in crbug.com/837798.
Labels: zine-triaged
Blockedon: 837798
Owner: yyushkina@chromium.org
Status: Assigned (was: Untriaged)
Status: WontFix (was: Assigned)
This is obsolete starting in M69.

Sign in to add a comment