Issue metadata
Sign in to add a comment
|
Security: Stored passwords easily retrievable in Chrome when user logged out of Google account
Reported by
cr...@photothermal.com,
Oct 5
|
||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS All passwords associated with Google user account can be easily retrieved even after user signed out , even if browser history cleared and Chrome closed. VERSION Chrome Version: Version 69.0.3497.100 (Official Build) (64-bit) Operating System: Windows 7 Professional SP1 REPRODUCTION CASE Here's how to reproduce the issue: 1) Sign into a Google User account in Chrome. 2) Navigate to a website requiring a username and password (e.g. a webmail account like Outlook Web App). 3) Enter the username and password and accept Google's offer to save the password. 4) Bookmark the site. 5) Close the tab with the site. 5) Log out from the Google user account (and you can even close Chrome and clear the browsing history). 6) Re-open Chrome, do *not* log on to a user account 7) Click on the previously bookmarked site and navigate to the username/password entry. Chrome autofills the password, even when logged out of the Google account. (This is already a problem.) 8) Right click on the password field and click on "Show all saved passwords" 9) Pick any of the passwords and click on the eye icon to show the password. 10) Simply entering a local active domain password at this point will show the password. This vulnerability exposes every Google user password on every computer where they have (1) ever logged in and (2) saved a bookmark. This is a critically common use case, for example shared computers in schools and universities where a student logs onto their GoogleDocs account or in my case at a company where we have computers running scientific instruments commonly accessible to multiple users. Simply using this computer to check email or logging onto GoogleDocs has permanently exposed passwords, even when the user is logged out. Users will expect and should reasonably assume that their data is secure if they are logged out of the Google account. Thanks for your attention to this issue.
,
Jan 12
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by jialiul@chromium.org
, Oct 5