New issue
Advanced search Search tips

Issue 866481 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 24
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: able to sync other clients passwords and websites information from their saved chrome passwords, etc

Reported by spsinw...@gmail.com, Jul 23

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://chromium.googlesource.com
/chromium/src/+/master/docs/security/faq.md

Please see the following link for instructions on filing security bugs:
https://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.

VERSION
Chrome Version: [67.0.3396.87] + [stable]
Operating System: [iOS, 11.4.1 chrome stableand service pack level

REPRODUCTION CASE
 On a number of times I have been able to obtain other clients password history and website identity and sign on information. I have it saved in my account and it has multiple unknown persons sign on information of passwords and account name or numbers. Has been able to obtain many people's passwords and sign on information from their accounts from Google through syncing it with my account. I also have been able to get a few accounts pictures from Google photos as well. I have been able to get full control of bank information and  much more personal information from all apps that had saved information. I am able to send the security leak and the way I have been able to get the security information. I also am wondering if it would be possible to get rewarded for the security information and how it's done.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace *with symbols*, registers,
exception record]
Client ID (if relevant): [see link above]
 
Labels: Needs-Feedback
Hi,

Can you please provide further details on your observed leak of data? This will help us determine what the issue might be and let you know if it's eligible for our bug bounty program.

See https://www.google.com/about/appsecurity/chrome-rewards/ for more information about the steps you need to follow to ensure eligibility for a bounty.
Labels: -Needs-Feedback
Status: WontFix (was: Unconfirmed)
Closing this out for now since there's nothing actionable for us here. Please file a new bug with additional details if you'd like to report a chrome vulnerability that you're aware of.
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 31

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment