New issue
Advanced search Search tips

Issue 861640 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 9
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: I can view google accounts contacts, despite it's restricted.

Issue description

Hi,

I work for the Local Police in Antwerp Belgium.

We use google accounts for our mobile devices with a company account.  We acces those via https://admin.google.be.

But I found out that when I wanted to acces the contacts of an account. Example:
SMA00002540@politie.antwerpen.be or SMA00002532@politie.antwerpen.be wich are google accounts of our company.  If a go to the apps button 'top right' and select contacts -> I get a message that acces is restricted.

However, if I press back and than choose the option in the middle of the screen wich sais 'go to contacts' it goes through.  This works on multiple accounts.
So if via one way I get no acces throug to restriction settings and it works via another way.. I suppose this is a security bug?  

As a governement institute security is highly important also.. 
I've read that for reporting security bugs there is a reward program.  So rewards as read on the webpage are more then welcome off course.  

My contact info:

Yves Solignac
gsm: +32 0487604930
mail: yves.solignac@politie.antwerpen.be
IT department Antwerp Police

Kind regards,

Yves
 
update: I tested this on Windows 10 pro with chrome Version 67.0.3396.99 (Official Build) (64-bit)
Status: WontFix (was: Unconfirmed)
Thanks for the report.

Your issue doesn't sound like a problem with Chrome, so this is not the right tracker for it. It might be an access control problem in G Suite.

Security bugs in Google products and services other than Chrome can be reported through https://goo.gl/vulnz. It also might be appropriate to escalate through Google enterprise support for your organization.
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 16

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment