LastPass, 1Password, and Bitwarden extensions are vulnerable to clickjacking attacks

Clickjacking Vulnerabilities Expose Password Managers to Attacks
Photo: rebuscando.info

Clickjacking Vulnerabilities Expose Password Managers to Attacks

Popular password managers including 1Password, Bitwarden, and LastPass have been found vulnerable to clickjacking attacks, putting millions of users at risk. At the DEF CON 33 conference, security researcher Marek Tóth demonstrated how these flaws can be exploited, allowing attackers to steal sensitive data like login credentials and financial details. The affected platforms also include Enpass, iCloud Passwords, and LogMeOnce. Tóth’s research shows that attackers can manipulate browser extensions to overlay invisible buttons or forms, tricking users into clicking on hidden elements. The exploit involves making parts of the password manager’s interface transparent or covering them with fake elements. Once triggered, these attacks can silently autofill sensitive data, exposing it to malicious actors. The researcher demonstrated the attack through live proof-of-concept demos, highlighting the potential risks to millions of users. Several vendors, such as Bitwarden, have already released patches, but others, including LastPass and 1Password, initially downplayed the severity of the vulnerabilities. Experts recommend that users disable autofill features in affected extensions until fixes are widely deployed.

Leave a Reply

Your email address will not be published. Required fields are marked *