Google Chrome Password Safe Exposes Master Key in Plaintext

This is close to the worst possible design failure, if not the worst.

This master key, known as the security domain secret, is temporarily sent to Chrome when a device registers or recovers access to the account.

Unit 42 initially found that Chrome exposed the secret in plaintext through its internal FIDO logs. Google removed the secret from the logs after the researchers reported the issue, but Unit 42 says it is still sent to Chrome and remains temporarily accessible in the browser’s process memory.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.