Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Elon Musk suggests successive xAI withdrawals were a push, not a pull

Microsoft announced that hackers are exploiting a critical zero-day bug to target Windows and Office users.

How to join a16z’s highly competitive Speedrun startup accelerator program

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » DOM-based extension ClickJacking exposes popular password managers to credentials and data theft
Identity

DOM-based extension ClickJacking exposes popular password managers to credentials and data theft

userBy userAugust 20, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

August 20, 2025Ravi LakshmananVulnerability/Browser Security

It has been discovered that popular password manager plugin web browsers could click on security vulnerabilities that could be exploited to steal account eligibility, two-factor authentication (2FA) codes and credit card details under certain conditions.

The technique dubbed a Document Object Model (DOM)-based extension by independent security researcher Marek Tóth, who published his findings at the DEF CON 33 Security Conference earlier this month.

“Attackers can now steal user data (credit card details, personal data, and login credentials including TOTP) anywhere on attacker-controlled websites,” Tóth said. “The new techniques are common and can be applied to other types of extensions.”

Cybersecurity

ClickJacking, also known as UI Redressing, refers to the type of attack in which a user is tricked into performing a series of actions on a website that appears to be harmless on the surface, such as by inadvertently performing an attacker’s bid, such as by clicking a button.

A new technique detailed by Tóth involves manipulating UI elements on web pages that inject browser extensions into the DOM, essentially using malicious scripts.

The study focuses specifically on 11 popular password manager browser add-ons ranging from 1 password to iCloud passwords, all of which were susceptible to DOM-based extension clickjacking. Collectively, these extensions have millions of users.

To stop attacks, all bad actors have to do is create fake sites with intrusive pop-ups like login screens and cookie consent banners, but also embed an invisible login form and click on the site to close the pop-up, so the password manager automates the credentials and excludes them on the remote server.

“All password managers met their credentials not only in the “main” domain, but also in all subdomains,” explained Tóth. “Attackers can easily spot XSS or other vulnerabilities and steal a user’s saved credentials with a single click (10 out of 11) including TOTP (9 out of 11). Passkey authentication could also be exploited in some scenarios.”

Following responsible disclosure, six vendors have not yet released fixes for the defects –

1Password Password Manager 8.11.4.27 Apple Icloud Passwords 3.1.25 Bitwarden Password Manager 2025.7.0 Enpass 6.11.6 LastPass 4.146.3 Logmeonce 7.12.4

Identity Security Risk Assessment

Software supply chain security company Socket, which independently reviewed the survey, said that Bitwarden, Enpass and iCloud passwords are actively working on fixing, with 1Password and LastPass markings useful. We are also contacting US-Cert to assign the CVE identifier for the identified issue.

Until the fix is available, users are advised to disable the password manager’s autofill feature and use copy/paste only.

“For Chromium-based browser users, use the extended settings[オン]Click[オン]”We recommend configuring site access to the site,” Tóth said. “This configuration allows users to manually control the autofill feature.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article“Why do you want to go?”: Readers respond to the hypothetical 400-year voyage to Alpha Centauri
Next Article Humanity bundles Claude Code into Enterprise Plan
user
  • Website

Related Posts

First malicious Outlook add-in discovered that steals over 4,000 Microsoft credentials

February 11, 2026

APT36 and SideCopy launch cross-platform RAT campaign against Indian companies

February 11, 2026

Public training opens the door to crypto mining in Fortune 500 cloud environments

February 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Elon Musk suggests successive xAI withdrawals were a push, not a pull

Microsoft announced that hackers are exploiting a critical zero-day bug to target Windows and Office users.

How to join a16z’s highly competitive Speedrun startup accelerator program

Why are the economics of orbital AI so cruel?

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.