New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 867734 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Last visit > 30 days ago
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug



Sign in to add a comment

Security: Chrome keeps saving passwords even for website that is listed as "Never Saved"

Reported by jpu2...@gmail.com, Jul 26

Issue description

VULNERABILITY DETAILS
Please provide a brief explanation of the security issue:
 
By allowing Google Chrome to save the username and password of a particular website, it looks like even after you've changed the settings and tell Chrome that you no longer want it to remember that website's login credentials by removing it from remembered passwords and adding it to "Never Saved" (via chrome://settings/passwords), Chrome will still populate the username/password fields of the said website. The most alarming part of this issue is that Chrome doesn't even ask to remember your credentials anymore, but somehow it still remembers and populates them at the login screen. I tried it on multiple attempts, but Chrome is still remembering and populating my login credentials. I was using Facebook.com

VERSION
Chrome Version: [Version  68.0.3440.75]
Operating System: [Windows 7 64-bit, Professional, Service Pack 1]

REPRODUCTION CASE:
The issue can be reproduced by allowing Chrome to save your username and password of a particular website then later change to "Never Saved" via Chrome: chrome://settings/passwords. Then by visiting that website, Chrome still populates the username and password fields of the said website.

 
GoogleBug.JPG
54.3 KB View Download
Components: UI>Browser>Passwords
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
This isn't something that we'd usually consider a vulnerability due to the attack vector, but it may still be a bug. Passing this along to the right team since they'll have a better idea.

See https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Why-arent-physically_local-attacks-in-Chromes-threat-model for more information.
Owner: nepper@chromium.org
Status: Assigned (was: Unconfirmed)
Assigning to nepper@ for triaging.
Labels: Pri-2
Setting defect without priority to Pri-2.

Sign in to add a comment