Security: Smart lock icon is displayed with username/password even after log out from gmail.
Reported by
raguramj...@gmail.com,
May 24 2018
|
|||||||||||||||
Issue descriptionVULNERABILITY DETAILS Google smart lock icon (key) is displayed with username/password even after log out from gmail. VERSION Chrome Version: Version 66.0.3359.181 (Official Build) (64-bit) Operating System: Windows 10 Enterprise : version 1703 OS build : 15063.1029 REPRODUCTION CASE 1. log in to gmail with username/password in google chrome 2. user can notice Google smart lock icon(key) is displayed with username/password to save or never. 3. user logged out from the gmail in google chrome 4. user can still notice the Google smart lock icon(key), upon clicking the icon, user can view gmail credentials 5. try to view a different website,in the same tab (google.com, or anyother website), still the icon remains in the url tab. To avoid this, the tab has to be closed to keep the gmail credentials safe, it happens for other websites too, like facebook etc. FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION Type of crash: tab Crash State: NA Client ID (if relevant): [see link above]
,
May 25 2018
In both the case, gmail & facebook. I haven't saved my credentials. I will upload a new video, with the your suggestion.
,
May 25 2018
Thank you for providing more feedback. Adding the requester to the cc list. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 25 2018
Also observed the smartlock icon, remains in the same tab for the certain amount of time (presuming some timeout on the icon)
,
May 25 2018
Video attached.
,
May 25 2018
Also let me know, is this bug eligible for chrome rewards!
,
May 25 2018
https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Why-arent-physically_local-attacks-in-Chromes-threat-model
,
May 28 2018
,
May 29 2018
Unable to reproduce the issue on Win-10 using chrome reported version #66.0.3359.181 and latest canary #68.0.3440.7. Attached a screen cast for reference. Following are the steps followed to reproduce the issue. ------------ 1. logged in to gmail with username/password in google chrome 2. Observed a Google smart lock icon(key) is displayed with username/password to save or never. 3. Logged out from the gmail in google chrome. 4. Observed that the Google smart lock icon(key) disappeared after logging out. raguramji.d@ - Could you please check the issue on latest canary #68.0.3440.7 by creating a new profile without any apps and extensions and please let us know if the issue still persist or not. he latest chrome builds can be downloaded from the below URL: https://www.chromium.org/getting-involved/dev-channel Thanks...!!
,
Jun 19 2018
This is a manual saving fallback. It's active for 90 seconds after last character typed into the form. I'm concerned that the bubble didn't pop up automatically in this case. dvadym@, do you know if we again regressed on Gmail recently?
,
Jun 21 2018
I don't know anything about regressions on gmail
,
Jun 26 2018
Could you please give us a resolution for this at the earliest. Currently, I am accessing gmail only via incognito mode. Which is irritating at times, As I have to enter the email id everytime, where as in normal mode, the email ids are saved, only i have to enter password to access the account.
,
Jun 26 2018
Thank you for providing more feedback. Adding the requester to the cc list. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 26 2018
I appreciate the inconvenience expressed in #12, but to help us help you, it would be great to have the question from #9 answered.
,
Jun 27 2018
Answering the question#9, yes, it is happening only for raguramji.d@gmail.com, for other email id, the smart key is vanished upon signout.
,
Jun 27 2018
Thank you for providing more feedback. Adding the requester to the cc list. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 27 2018
I'm afraid that #15 did not answer what #9 asked about. #9 asks for getting the newest Chrome Canary, creating a new profile without any apps and extensions and trying to reproduce the issue. I tried to reproduce on my machine (GNU/Linux, Chrome 67.0.3396.99, clean profile), but could not -- the key icon disappears as soon as I log out of Gmail. Vasilii, as for your concern in #10 -- could it be that Chrome no longer pops the bubble open if the user ignored it repeatedly? Also, do you know if the timeout is enabled? I could not manage to trigger it.
,
Jun 28 2018
I have downloaded the latest chrome (Version 67.0.3396.99 (Official Build) (64-bit)) from https://www.chromium.org/getting-involved/dev-channel and uninstalled all the plugins, still the smart key is present in the url tab, even after log-out from gmail account. As i have mentioned earlier it is happening only for raguramji.d@gmail.com, for other email id, the smart key is vanished upon signout.
,
Jun 28 2018
Attached the screen shot.
,
Jun 28 2018
Thank you for providing more feedback. Adding the requester to the cc list. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 2
Do you see the password bubble popping up automatically when you log in to Gmail? Does it depend on the account?
,
Jul 3
No, It is not popping up (not showing username/password to save) on any of my account, but there is a key icon on the url tab. only for one email account, it stays in the url tab even after signing out (till the timeout -approx - 120sec), which, for other email ids, it's gone soon after the signout.
,
Jul 3
All right. We don't detect the successful sign-in on Gmail and stay in the manual saving mode for 90 seconds. It's expected. The user can close the tab, or wait 90 seconds, or open the bubble and click "Never". I think those are viable actions. Again, we should fix the rootcause and show the bubble automatically on Gmail.
,
Jul 3
The actual problem is not stopped there, after signout from gmail, it shows the lock key with gmail account information, if I tried to open another page like facebook,twitter,etc , which takes user credential, then the lock key bubble cycle is refreshed with that page credential, along with the 90 sec timeout(reset). The only available option, I have right now to avoid this is close the tab, which is the actual issue.
,
Nov 29
vabr going hobby only -> reducing involvement. Please contact me directly in urgent matters.
,
Jan 11
Setting defect without priority to Pri-2. |
|||||||||||||||
►
Sign in to add a comment |
|||||||||||||||
Comment 1 by elawrence@chromium.org
, May 24 2018Summary: Security: Smart lock icon is displayed with username/password even after log out from gmail. (was: Security: Google smart lock icon (key) is displayed with username/password even after log out from gmail.)