Zero-Day Vulnerability allow attackers to steal users data Found in Password Managers( 1Password, Bitwarden, LastPass, Enpass, iCloud Passwords, and LogMeOnce remain unpatched— still vulnerable)
Zero-Day Vulnerability allow attackers to steal users data Found in Password Managers( 1Password, Bitwarden, LastPass, Enpass, iCloud Passwords, and LogMeOnce remain unpatched— still vulnerable)
Just a moment...
cross-posted from: https://programming.dev/post/36006277
Independent verification and publication by Socket Security.
Fixed: NordPass, ProtonPass, RoboForm, Dashlane, Keeper
Still vulnerable: Bitwarden, 1Password, iCloud Passwords, Enpass, LastPass, LogMeOnce
It's a clever attack but if I understand correctly it requires malicious script to be injected into a trusted webpage (ie. one that you normally log in to). This limits the utility of the attack, since any script injection vulnerability would already allow exfiltration of credentials that are entered manually when you log in to the site, password manager or not. The difference with this attack is that the attacker doesn't have to wait for you to log in, they just trick the password manager into autofilling the credentials straight away.