Issue metadata
Sign in to add a comment
|
Automated security scan results for Chrome on Android
Reported by
iranamoa...@gmail.com,
Jun 11 2018
|
||||||||||||||||||||
Issue description
VULNERABILITY DETAILS
ADB Backup is ENABLED for this app (default: ENABLED).ADB Backup is a good tool for backing up all of your files. If it's open for this app, people who have your phone can copy all of the sensitive data for this app in your phone (Prerequisite: 1.Unlock phone's screen 2.Open the developer mode). The sensitive data may include lifetime access token, username or password, etc.
VERSION
Platform: Android
Package Name:chrome
Package Version Name: 64.0.3282.137
Package Version Code: 328213711
REPRODUCTION CASE
ADB Backup is a good tool for backing up all of your files. If it's open for this app, people who have your phone can copy all of the sensitive data for this app in your phone (Prerequisite: 1.Unlock phone's screen 2.Open the developer mode). The sensitive data may include lifetime access token, username or password, etc.
Security case related to ADB Backup:
1.http://www.securityfocus.com/archive/1/530288/30/0/threaded
2.http://blog.c22.cc/advisories/cve-2013-5112-evernote-android-insecure-storage-of-pin-data-bypass-of-pin-protection/
3.http://nelenkov.blogspot.co.uk/2012/06/unpacking-android-backups.html
Reference: http://developer.android.com/guide/topics/manifest/application-element.html#allowbackup
Full Report of app Test is attached for more Information.
,
Jun 11 2018
No, nothing interesting in the report.
,
Sep 18
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by palmer@chromium.org
, Jun 11 2018Labels: OS-Android
Owner: rsesek@chromium.org
Status: Assigned (was: Unconfirmed)
Summary: Automated security scan results for Chrome on Android (was: Security: ADB Backup is ENABLED for this app (default: ENABLED).)