New issue
Advanced search Search tips

Issue 884258 link

Starred by 1 user

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug

Blocking:
issue 674151



Sign in to add a comment

Autofill offers to save CC#/CVC as username/password on kayak.com

Project Member Reported by durgapandey@chromium.org, Sep 14

Issue description

Chrome Version: 70.0.3534.4 (Official Build) dev (64-bit)
OS: MacOS 10.13.6

What steps will reproduce the problem?
(1) Go to kayak.com
(2) Buy a ticket where the transaction happens on Kayak.com itself
(3) Observe that Chrome prompts to save CC/CVC as username/passw for site

What is the expected result?
Chrome should not offer to save any username password, and should likely offer to save the card.

What happens instead?
Observe that Chrome prompts to save CC/CVC as username/passw for site


Please use labels and text to provide additional information.

If this is a regression (i.e., worked before), please consider using the
bisect tool (https://www.chromium.org/developers/bisect-builds-py) to help
us identify the root cause and more rapidly triage the issue.

For graphics-related bugs, please copy/paste the contents of the about:gpu
page at the end of this report.


 
Blocking: 674151
Components: UI>Browser>Passwords
Labels: Hotlist-Polish
Owner: ----
Status: Available (was: Untriaged)
Thanks for the report.

It would be interesting to know the name of the field with the CVC (appears also in about:password-manager-internals). I tried to reproduce but could not find a flight paid for on kayak itself. With the name, we could tweak the regexp used to recognise the CVC fields.

Apart from that, I am also working right now on a way to make the server more useful for classifying CVC fields.

Sign in to add a comment