Researcher Exposes Zero-Day Clickjacking Vulnerabilities in ...
Blog post from Socket
At DEF CON 33, security researcher Marek Tóth revealed several unpatched zero-day clickjacking vulnerabilities affecting browser-based plugins of popular password managers such as 1Password, Bitwarden, LastPass, and LogMeOnce, among others. These vulnerabilities allow hackers to steal sensitive data like credit card details and login credentials when users visit malicious websites, particularly if the sites have cross-site scripting or subdomain takeover vulnerabilities. Despite the potential risks, some vendors have been slow to respond, with 1Password and LastPass marking the issues as merely "informative," and LogMeOnce failing to respond entirely. Tóth demonstrated the vulnerabilities through live proof of concepts, highlighting the ease with which users can be tricked into leaking data. Although some password managers are working on fixes, the implementation of robust defenses remains challenging due to the balance between security and usability. Tóth recommends users exercise caution and consider disabling manual autofill or changing browser extension settings to mitigate risks while vendors are urged to adopt additional security measures like confirmation dialogs before autofilling.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.