Open Bug 2029497 Opened 4 months ago Updated 3 months ago

Firefox password overwritten + new password landing on Chrome without consent

Categories

(Toolkit :: Password Manager, defect)

Firefox 148
defect

Tracking

()

UNCONFIRMED

People

(Reporter: rubinsteinart, Unassigned, NeedInfo)

Details

Attachments

(3 files)

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:148.0) Gecko/20100101 Firefox/148.0

Steps to reproduce:

I used Firefox on my Surface Go tablet today, as I do every single day. System is Windows 10.

For the first time, I had a double issue come up... and it's very disturbing:

  • Google Chrome has been installed for a while on my device but was NOT open at all: I do not use it more than 3-5 times a year if I need to troubleshoot something regarding a specific website. It has no passwords saved, usually no history or cookies either.

1 - Went on a website via Firefox, tried to open an existing account that should've autofilled. Firefox erased an existing password in favor of a "strong password" without me agreeing to saving/updating any new login info.

Note: You can see "Used" on April 2 (today) because I didn't know my old password had be overwritten yet. I found out when I couldn't sign in and opened my password manager. The new password didn't actually work since it was NOT the actual password for my account.

This forced me to try and retrieve my account by clicking "forgot password" on the website. The email took too long to arrive so I decided to open Chrome to troubleshoot.

2- As I go on the same website via Chrome, to repeat the "forgot password" step again that new "strong password" from Firefox pops up on Chrome and autofills!!!

I want to know what is going on with our private data, this never happened to me before and is UNSAFE!

Actual results:

1- Firefox erased overwrote a saved password (from 2024) in favor of a new "strong password" as if I was creating a new account (see screenshot)

2- I open Chrome (was not running prior) and that "strong password" showed up on Chrome as soon as I opened the browser. Except I NEVER allowed for Chrome or Firefox to exchange passwords!

Expected results:

  • No overwritting of existing password
  • no password sent to google chrome

The Bugbug bot thinks this bug should belong to the 'Toolkit::Password Manager' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.

Component: Untriaged → Password Manager
Product: Firefox → Toolkit

Hello,

Thank you so much for the report. We have not heard of Firefox behaving like this before, so we are investigating the matter deeply.
For more context, would you be able to provide

  • a screenshot of the filled field on the website both in Chrome and Firefox (of course without revealing the password)
  • do you say "strong password" because it looks like the auto-generated one?
  • do you have any extensions installed on Firefox?

Thank you so much for your help.

Hi Johannes,
Thank you for investigating and following up.

  • I'll answer your second question first: by "strong password" I meant one auto-generated by Firefox, yes. I believe they're labeled that way on the browser. That auto-generated password overwrote the one I came up with in 2024 (or even earlier, honestly).

  • First question: The screenshot I attached in my original message is the only one I took back then. I got spooked and frustrated by what I saw on Chrome so I immediately I deleted the password, removed the browsing data and closed Chrome. I then returned to Firefox to check for any setting allowing this type of username/password sharing. I found none.

I have yet to try and retrieve my account on the website I was on. Because I still haven't modified my password since the overwriting incident, I can still capture the page as it was on April 2 (see attached). As for Chrome, I no longer have anything saved so there's no autofilling possible. But if I manually enter the same username and password, you'll see the same issue of not being able to access my account.

What I can say is that the strong passwords auto-generated (or suggested) by Firefox look nothing like the ones I create myself, so they are very easy for me to differentiate. The username and password on Chrome matched Firefox's new password (auto-generated on April 2). When I opened Chrome's password manager, that brand new password/login was the only one there. And apart from the single website I visited that day, I can confirm there was no prior browsing history, cookies, bookmarks or saved data of any kind on there. When I open(ed) Chrome the welcome page is a google.com tab and the suggestion to make Chrome my default browser under the address bar.

  • Third question: the extensions I have, have been installed for a long time and they are auto-updated. They are Ublock origin (always active), Proton VPN (inactive/disabled), Express VPN (inactive/disabled), Keepa (inactive).

Lastly, any time I've imported/exported passwords in the past (between devices or browsers), it was 100% voluntary, manual and never automatically synched from one browser to the other. I also haven't had the need to export anything in a very, very long time, likely years. I never had the issue described in my report before, and haven't had that issue since... But so far the only password I've created/saved since April 2 was for bugzilla.mozilla.org, so perhaps no reason for that to show up on Chrome? Not sure. Beyond Chrome and Firefox, the last thing that comes to mind is Windows, but Windows 10 never did that and has had no updates since November 2025.

Thanks again.

The severity field is not set for this bug.
:mtigley, could you have a look please?

For more information, please visit BugBot documentation.

Flags: needinfo?(mtigley)
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: