New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 851235 link

Starred by 3 users

Issue metadata

Status: Assigned
Owner:
Last visit > 30 days ago
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: ----



Sign in to add a comment

Auto-fill Security Concern

Reported by mabre...@mtu.edu, Jun 9 2018

Issue description

This template is ONLY for reporting privacy issues. Please use a different
template for other types of bug reports.

Please see http://www.chromium.org/Home/chromium-privacy for further
information.

PRIVACY ISSUE
Please provide a brief summary of the privacy issue.

When filling out a credit card # on amazon.com the auto-fill options will attempt to fill in the credit card #, and by trial and error I am able to guess the full credit card #. 

VERSION:
Chrome Version: [Version 66.0.3359.181 (Official Build) (64-bit)
Operating System: Microsoft Windows

REPRODUCTION STEPS
Please provide detailed reproduction steps, and any additional
information below. Include an URL demonstrating the issue and attach a
screenshot if
applicable. Be sure to include in your description how this issue
affects your privacy.

If my credit card number is 1234 5678 1234 5678, when I type "1" the auto-fill drop down bar shows up showing "Mastercard 1234 -xxxx-xxxx-5678 MM/DD" (or something very similar). When I continue to type numbers the auto-fill option will either disappear or remain on the screen, depending whether or not I guess the correct number. I was able to guess the full CC # very quickly by using the auto-fill bar display as confirmation. 

This issue can obviously be mitigated by turning off the auto-fill options in Chrome, so that's what i'm going to do. 

 
Components: UI>Browser>Autofill
You could also go to chrome://settings/autofill and click edit to view the credit card or autofill it and look at the filled data, so I think someone who is able to login to your computer would have access to this data anyway.

Cc: se...@chromium.org
Owner: durgapandey@chromium.org
Status: Assigned (was: Untriaged)
+durgapandey@

Like dullweber@ mentioned, this is information you can see in the settings. The benefit I see for the user is that they can filter the suggestions if they remember the first number(s) of the cards they want to fill.

This is not the case for masked server card (from Payments) since we know only about the last 4 digits.
Owner: nepper@chromium.org

Sign in to add a comment