New issue
Advanced search Search tips

Issue 892655 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Oct 5
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Stored passwords easily retrievable in Chrome when user logged out of Google account

Reported by cr...@photothermal.com, Oct 5

Issue description

VULNERABILITY DETAILS
All passwords associated with Google user account can be easily retrieved even after user signed out , even if browser history cleared and Chrome closed.

VERSION
Chrome Version: Version 69.0.3497.100 (Official Build) (64-bit)
Operating System: Windows 7 Professional SP1

REPRODUCTION CASE
Here's how to reproduce the issue:
1) Sign into a Google User account in Chrome.
2) Navigate to a website requiring a username and password (e.g. a webmail account like Outlook Web App).
3) Enter the username and password and accept Google's offer to save the password.
4) Bookmark the site.
5) Close the tab with the site.
5) Log out from the Google user account (and you can even close Chrome and clear the browsing history).
6) Re-open Chrome, do *not* log on to a user account
7) Click on the previously bookmarked site and navigate to the username/password entry.  Chrome autofills the password, even when logged out of the Google account.  (This is already a problem.)
8) Right click on the password field and click on "Show all saved passwords"
9) Pick any of the passwords and click on the eye icon to show the password.
10) Simply entering a local active domain password at this point will show the password.

This vulnerability exposes every Google user password on every computer where they have (1) ever logged in and (2) saved a bookmark. This is a critically common use case, for example shared computers in schools and universities where a student logs onto their GoogleDocs account or in my case at a company where we have computers running scientific instruments commonly accessible to multiple users. Simply using this computer to check email or logging onto GoogleDocs has permanently exposed passwords, even when the user is logged out. Users will expect and should reasonably assume that their data is secure if they are logged out of the Google account.

Thanks for your attention to this issue.
  
 
Status: WontFix (was: Unconfirmed)
Based on your description, your passwords are saved in the profile. Even if you logout your google account in content, restart Chrome, you're still using the same profile. 

When you clear your browsing history, by default your saved passwords are not cleared. If you want to clear them too, go to 
chrome://settings --> "Clear browsing data" --> "Advanced" --> choose "Passwords"

Thanks for your reporting. I'm closing this one as working as intended. 
Project Member

Comment 2 by sheriffbot@chromium.org, Jan 12

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment