New issue
Advanced search Search tips

Issue 877947 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 126398
Owner: ----
Closed: Aug 27
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Security



Sign in to add a comment

Stored passwords can be viewed by a simple hack in dev tools

Reported by luca.vig...@grammelot.eu, Aug 27

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36

Steps to reproduce the problem:
1. Open any login page where you had previously decided to save login details
2. Password field is auto filled in but password is replaced by starts (as expected)
3. If you try to copy and pase the password field, nothing is copied to protect password (as expected)
4. Now right-click on password field and select "inspect" (or open developer tools and select the password filed from there)
5. In developer tools, change input type from "password" to "text" and the password will appear

What is the expected behavior?
User should not be able to visualize saved password

What went wrong?
Password can bi viewed by changing the input type from "password" to "text" in developers tools. Maybe in this case, when changing from "password" to "text" the input contents should be removed automatically.

Did this work before? No 

Chrome version: 68.0.3440.106  Channel: stable
OS Version: 
Flash Version:
 
Status: WontFix (was: Unconfirmed)
Thanks for the report.

Unfortunately this is not something Chrome can prevent. The Chrome Security FAQ explains why we don't consider this a vulnerability: https://dev.chromium.org/Home/chromium-security/security-faq#TOC-What-about-unmasking-of-passwords-with-the-developer-tools-
Mergedinto: 126398
Status: Duplicate (was: WontFix)
Project Member

Comment 3 by sheriffbot@chromium.org, Dec 4

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment