[GH-ISSUE #5153] Secure note edited hidden field is unprotected #39188

Closed
opened 2026-04-23 17:53:00 -05:00 by GiteaMirror · 4 comments
Owner

Originally created by @ivndbt on GitHub (May 8, 2025).
Original GitHub issue: https://github.com/bitwarden/android/issues/5153

Steps To Reproduce

  1. Go to "My Vault"
  2. Click on "Secure Notes"
  3. Add a new note with "Master password re-prompt" enabled and a custom field of type "Hidden"
  4. Save the note
  5. Open the newly created note and click "Edit"
  6. Enter your master password when prompted
  7. Click "Additional Options"
  8. Click the eye icon next to your hidden custom field and edit its value
  9. Click "Save" (top right)
  10. Open the note again and click on the "Password history: $number" link at the bottom

Expected Result

A master password prompt should appear before revealing the password history.

Actual Result

The history of the hidden custom field is shown in plain text without any password prompt.

Screenshots or Videos

No response

Additional Context

No response

Build Version

2025.3.0 (19983)

What server are you connecting to?

EU

Self-host Server Version

No response

Environment Details

No response

Issue Tracking Info

  • I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
Originally created by @ivndbt on GitHub (May 8, 2025). Original GitHub issue: https://github.com/bitwarden/android/issues/5153 ### Steps To Reproduce 1. Go to "My Vault" 2. Click on "Secure Notes" 3. Add a new note with "Master password re-prompt" enabled and a custom field of type "Hidden" 4. Save the note 5. Open the newly created note and click "Edit" 6. Enter your master password when prompted 7. Click "Additional Options" 8. Click the eye icon next to your hidden custom field and edit its value 9. Click "Save" (top right) 10. Open the note again and click on the "Password history: $number" link at the bottom ### Expected Result A master password prompt should appear before revealing the password history. ### Actual Result The history of the hidden custom field is shown in plain text without any password prompt. ### Screenshots or Videos _No response_ ### Additional Context _No response_ ### Build Version 2025.3.0 (19983) ### What server are you connecting to? EU ### Self-host Server Version _No response_ ### Environment Details _No response_ ### Issue Tracking Info - [x] I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
GiteaMirror added the bugapp:password-manager labels 2026-04-23 17:53:01 -05:00
Author
Owner

@S-Kakar commented on GitHub (May 8, 2025):

Thank you for your report! We've added this to our internal board for review.
ID: PM-21335

<!-- gh-comment-id:2861770994 --> @S-Kakar commented on GitHub (May 8, 2025): Thank you for your report! We've added this to our internal board for review. ID: PM-21335
Author
Owner

@NovaSilentium commented on GitHub (May 9, 2025):

Hi there,

Thank you for your report!

I was able to reproduce this issue, and I have flagged this to our engineering team.

If you wish to add any further information/screenshots/recordings etc., please feel free to do so at any time - our engineering team will be happy to review these.

Thanks once again!

<!-- gh-comment-id:2865515736 --> @NovaSilentium commented on GitHub (May 9, 2025): Hi there, Thank you for your report! I was able to reproduce this issue, and I have flagged this to our engineering team. If you wish to add any further information/screenshots/recordings etc., please feel free to do so at any time - our engineering team will be happy to review these. Thanks once again!
Author
Owner

@closebot-bw commented on GitHub (Feb 11, 2026):

⚠️ Stale Issue Notice

This issue has been automatically marked as stale due to inactivity. It will be closed in 2 weeks (February 25, 2026) if no further activity occurs.

If this issue is still relevant and you would like to keep it open, please:

  • Comment on this issue to show continued interest
  • Provide any additional information or updates
  • Confirm that the issue still exists in the latest version

Thank you for your contribution to this project! 🙏

<!-- gh-comment-id:3886597418 --> @closebot-bw commented on GitHub (Feb 11, 2026): ⚠️ **Stale Issue Notice** This issue has been automatically marked as stale due to inactivity. It will be closed in **2 weeks** (February 25, 2026) if no further activity occurs. If this issue is still relevant and you would like to keep it open, please: - Comment on this issue to show continued interest - Provide any additional information or updates - Confirm that the issue still exists in the latest version Thank you for your contribution to this project! 🙏
Author
Owner

@ivndbt commented on GitHub (Feb 11, 2026):

It seems fixed to me.

<!-- gh-comment-id:3886702207 --> @ivndbt commented on GitHub (Feb 11, 2026): It seems fixed to me.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#39188