New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 847987 link

Starred by 2 users

Issue metadata

Status: Assigned
Owner:
Last visit > 30 days ago
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: ----



Sign in to add a comment

Issue pertaining to Facebook Login ID and Password

Reported by shonetho...@gmail.com, May 30 2018

Issue description

This template is ONLY for reporting privacy issues. Please use a different
template for other types of bug reports.

Please see http://www.chromium.org/Home/chromium-privacy for further
information.


PRIVACY ISSUE
Able to see saved ID and password of someone else who has previously used my Chrome.

VERSION:
Chrome Version: Version 65.0.3325.181 (Official Build) 32-bit
Operating System: Windows 7 Enterprise, Service Pack 1

REPRODUCTION STEPS
Reproduction Steps are in the attached file and screenshots are provided.

 
security bug.docx
461 KB Download
I believe this security glitch need to be resolved as soon as possible.
Components: Services>Sync
Owner: sabineb@chromium.org
Status: Assigned (was: Untriaged)
adding the contents of the attached document to this bug for convenience:
PRIVACY ISSUE
It has come to my notice that certain cookies in the Chrome could be of a potential threat to the many users who use this search engine worldwide. Chrome allows you to save passwords on your desktop to save the users time but this feature has a vulnerability and I had noticed it previously but I hadn’t reported this because I was busy in school work, however the same vulnerability has been observed by me and I just cannot refrain from reporting it to Google. I believe if this had been previously reported then Google would have fixed it but the issue still pertains. To simplify and to make the matter more understandable I have used a different fond below to report the issue/bug.

ISSUE:- I have been using Chrome for as long as I remember and I live with my family in New Delhi. Me and my father use Google Chrome for our regular day to day work one of the sites we commonly used is Facebook. We have saved both our passwords for the Facebook account in the Chrome in our laptop back in India. I have moved to the US to do my graduate studies and my parents are back home in India. While browsing Facebook using Chrome in US I am still able to see my father’s login ID and password for Facebook. One day during work I logged into my Facebook account but I noticed that something was not right. I had logged into my father’s Facebook account it took me a while to notice that because we have the same family and friends. I believe there is a potential risk to the feature of cookies in Chrome since I am able to login to my father’s account due to the save login ID and password feature in Chrome. Kindly look into this matter there is a huge potential risk for the users in case the person who accidently logged in takes undue advantage of the situation.
Chrome Version:- Version 65.0.3325.181 (Official Build) 32-bit
Operating System:- Windows 7 Enterprise, Service Pack 1
Reproduction Steps:-  To demonstrate the issue I will attach the page from where I have to login followed by the page after logging in. Note this is not my account but my father’s. I believe that the information that I will now share will remain secure.
Login Page

Page after Logging In

I believe this is a bug that can compromise on the security of the user. I am thinking on a solution for this problem. I guess providing better security features for the cookies is one great way to resolve this problem. Looking forward to hearing from you soon.
Owner: tschumann@chromium.org
Thanks for reporting this issue. 
We've investigated cases like this several times in the past and I understand that this is a disturbing experience for you. 
 
From you description it seems like multiple users (like you and your father) are syncing their data (from possible multiple devices) to the same account.

We'll try to figure out exactly how it happened. I have a few questions for you. It would be great to get the answers for all devices you know of (including the one used by your father):

1. Please open Chrome and go to menu -> settings and look for an email address (usually displayed at the top of settings). What email is shown? Is this your email address? 

2. Which devices do you use Chrome on? It’s helpful for us to know the operating system and Chrome version of each one. You can find the Chrome version in the menu -> About Google Chrome.

3. Please visit https://security.google.com/settings/security/activity and let us know if you see any unexpected devices associated with your account. If you do, please note the information displayed about the device before you remove it.


Sign in to add a comment