New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 846236 link

Starred by 3 users

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Security: Smart lock icon is displayed with username/password even after log out from gmail.

Reported by raguramj...@gmail.com, May 24 2018

Issue description

VULNERABILITY DETAILS
Google smart lock icon (key) is displayed with username/password even after log out from gmail.

VERSION
Chrome Version: Version 66.0.3359.181 (Official Build) (64-bit)
Operating System: Windows 10 Enterprise : version 1703 OS build : 15063.1029

REPRODUCTION CASE
1. log in to gmail with username/password in google chrome
2. user can notice Google smart lock icon(key) is displayed with username/password to save or never.
3. user logged out from the gmail in google chrome
4. user can still notice the Google smart lock icon(key), upon clicking the icon, user can view gmail credentials
5. try to view a different website,in the same tab (google.com, or anyother website), still  the icon remains in the url tab.

To avoid this, the tab has to be closed to keep the gmail credentials safe, it happens for other websites too, like facebook etc.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: tab
Crash State: NA
Client ID (if relevant): [see link above]

 
google chrome issue 2018-05-24-12-42-13.mp4
2.5 MB View Download
Labels: Needs-Feedback
Summary: Security: Smart lock icon is displayed with username/password even after log out from gmail. (was: Security: Google smart lock icon (key) is displayed with username/password even after log out from gmail.)
It's working as expected that the SmartLock icon remains in the omnibox while you are on the same site, even if you use a "log out" function (as Chrome has no way to recognize such an action).

It would be surprising if the lock icon remained if you navigate to another site as claimed in #5. Your video does not clearly demonstrate that; it seems to show you navigating from one site (Google) to another (Facebook) for which credentials were also stored. 

Instead of navigating to another site with stored credentials, please try re-recording the video and instead navigate to an unrelated site for which you have not stored credentials (e.g. https://example.com). 
In both the case, gmail  & facebook. I haven't saved my credentials.
I will upload a new video, with the your suggestion.
Project Member

Comment 3 by sheriffbot@chromium.org, May 25 2018

Cc: elawrence@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Also observed the smartlock icon, remains in the same tab for the certain amount of time (presuming some timeout on the icon)
Video attached.
google chrome issue captured on 2018-05-25-09-05-54.mp4
1.7 MB View Download
Also let me know, is this bug eligible for chrome rewards!
Components: UI>Browser>Passwords
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Why-arent-physically_local-attacks-in-Chromes-threat-model
Labels: Needs-Triage-M66
Cc: krajshree@chromium.org
Labels: Needs-Feedback Triaged-ET
Unable to reproduce the issue on Win-10 using chrome reported version #66.0.3359.181 and latest canary #68.0.3440.7.

Attached a screen cast for reference.

Following are the steps followed to reproduce the issue.
------------
1. logged in to gmail with username/password in google chrome
2. Observed a Google smart lock icon(key) is displayed with username/password to save or never.
3. Logged out from the gmail in google chrome.
4. Observed that the Google smart lock icon(key) disappeared after logging out.

raguramji.d@ - Could you please check the issue on latest canary #68.0.3440.7 by creating a new profile without any apps and extensions and please let us know if the issue still persist or not.
he latest chrome builds can be downloaded from the below URL:
https://www.chromium.org/getting-involved/dev-channel

Thanks...!!
846236.mp4
2.4 MB View Download
Cc: dvadym@chromium.org
This is a manual saving fallback. It's active for 90 seconds after last character typed into the form.

I'm concerned that the bubble didn't pop up automatically in this case. dvadym@, do you know if we again regressed on Gmail recently?
I don't know anything about regressions on gmail
Could you please give us a resolution for this at the earliest. Currently, I am accessing gmail only via incognito mode. Which is irritating at times, As I have to enter the email id everytime, where as in normal mode, the email ids are saved, only i have to enter password to access the account.
Project Member

Comment 13 by sheriffbot@chromium.org, Jun 26 2018

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 14 by vabr@chromium.org, Jun 26 2018

Labels: Needs-Feedback
I appreciate the inconvenience expressed in #12, but to help us help you, it would be great to have the question from #9 answered.
Answering the question#9, yes, it is happening only for raguramji.d@gmail.com, for other email id, the smart key is vanished upon signout.
Project Member

Comment 16 by sheriffbot@chromium.org, Jun 27 2018

Cc: vabr@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 17 by vabr@chromium.org, Jun 27 2018

Labels: Needs-Feedback
I'm afraid that #15 did not answer what #9 asked about. #9 asks for getting the newest Chrome Canary, creating a new profile without any apps and extensions and trying to reproduce the issue.

I tried to reproduce on my machine (GNU/Linux, Chrome 67.0.3396.99, clean profile), but could not -- the key icon disappears as soon as I log out of Gmail.


Vasilii, as for your concern in #10 -- could it be that Chrome no longer pops the bubble open if the user ignored it repeatedly? Also, do you know if the timeout is enabled? I could not manage to trigger it.
I have downloaded the latest chrome (Version 67.0.3396.99 (Official Build) (64-bit)) from https://www.chromium.org/getting-involved/dev-channel and uninstalled all the plugins, still the smart key is present in the url tab, even after log-out from gmail account. As i have mentioned earlier it is happening only for raguramji.d@gmail.com, for other email id, the smart key is vanished upon signout.
Attached the screen shot.
gmail Smartkey.JPG
85.9 KB View Download
Project Member

Comment 20 by sheriffbot@chromium.org, Jun 28 2018

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: OS-Windows
Do you see the password bubble popping up automatically when you log in to Gmail? Does it depend on the account?
No, It is not popping up (not showing username/password to save) on any of my account, but there is a key icon on the url tab. only for one email account, it stays in the url tab even after signing out (till the timeout -approx - 120sec), which, for other email ids, it's gone soon after the signout.
Status: Available (was: Unconfirmed)
All right. We don't detect the successful sign-in on Gmail and stay in the manual saving mode for 90 seconds. It's expected. The user can close the tab, or wait 90 seconds, or open the bubble and click "Never". I think those are viable actions.
Again, we should fix the rootcause and show the bubble automatically on Gmail.
The actual problem is not stopped there, after signout from gmail, it shows the lock key with gmail account information, if I tried to open another page like facebook,twitter,etc , which takes user credential, then the lock key bubble cycle is refreshed with that page credential, along with the 90 sec timeout(reset).

The only available option, I have right now to avoid this is close the tab, which is the actual issue.

Cc: -vabr@chromium.org
vabr going hobby only -> reducing involvement.
Please contact me directly in urgent matters.
Labels: Pri-2
Setting defect without priority to Pri-2.

Sign in to add a comment