LastPass Chrome & Firefox Extensions Affected by Critical Bug (Patched)

Bot

AI-powered Bot
Thread author
Apr 21, 2016
4,370
lastpass-chrome-firefox-extensions-affected-by-critical-bug.png


LastPass, the password vault that you were supposed to trust with your information, was affected by a critical security flaw. Thankfully, the company has already patched things up.

This wasn't even some very complicated problem, but rather a coding error. At least that's the opinion of Google's Tavis Ormandy, security expert that has detected numerous problems over the years, including the recent Cloudflare incident.

The white hat found the issue within the LastPass Chrome extension. According to Ormandy, the extension had an exploitable content script that could be attacked to extract passwords from the manager. It could also be pushed to execute commands on the victim's computer, which the Google hacker demonstrated easily.

"This script will proxy unauthenticated window messages to the extension. This is clearly a mistake," Ormandy writes.

Read more: LastPass Chrome & Firefox Extensions Affected by Critical Bug
 

Solarlynx

Level 15
Verified
Top Poster
Well-known
Apr 30, 2012
711
If that's the case, then Keepass can fix vulnerabilities much quicker than LastPass? You should be grateful that it was patched sooner rather than later.
Of course, I'm grateful to Lastpass and not only in this case. But this case woke up my uneasiness towards using password managers like Lastpass. And the question is still the same. Maybe Keepass is more safer? I just don't have enough knowledge to make certain answer. I used Keepass with Dropbox sync and was quite shure in my passwords database safety. At least KP is an open source.

One more thing about LP is that they moved to freemium for android users. Will they have enough cash to develop their product? The freemium options actually provide what most users need.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top