Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Smarter Healthcare Starts Now: The Power of Integrated Medical Devices

Google, sorry, that pixel event was Klinge Fest

Pixel 10, new Gemini features, Pixel Watch, and everything else announced at the Made by Google 2025 event

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » DOM-based extension ClickJacking exposes popular password managers to credentials and data theft
Identity

DOM-based extension ClickJacking exposes popular password managers to credentials and data theft

userBy userAugust 20, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

August 20, 2025Ravi LakshmananVulnerability/Browser Security

It has been discovered that popular password manager plugin web browsers could click on security vulnerabilities that could be exploited to steal account eligibility, two-factor authentication (2FA) codes and credit card details under certain conditions.

The technique dubbed a Document Object Model (DOM)-based extension by independent security researcher Marek Tóth, who published his findings at the DEF CON 33 Security Conference earlier this month.

“Attackers can now steal user data (credit card details, personal data, and login credentials including TOTP) anywhere on attacker-controlled websites,” Tóth said. “The new techniques are common and can be applied to other types of extensions.”

Cybersecurity

ClickJacking, also known as UI Redressing, refers to the type of attack in which a user is tricked into performing a series of actions on a website that appears to be harmless on the surface, such as by inadvertently performing an attacker’s bid, such as by clicking a button.

A new technique detailed by Tóth involves manipulating UI elements on web pages that inject browser extensions into the DOM, essentially using malicious scripts.

The study focuses specifically on 11 popular password manager browser add-ons ranging from 1 password to iCloud passwords, all of which were susceptible to DOM-based extension clickjacking. Collectively, these extensions have millions of users.

To stop attacks, all bad actors have to do is create fake sites with intrusive pop-ups like login screens and cookie consent banners, but also embed an invisible login form and click on the site to close the pop-up, so the password manager automates the credentials and excludes them on the remote server.

“All password managers met their credentials not only in the “main” domain, but also in all subdomains,” explained Tóth. “Attackers can easily spot XSS or other vulnerabilities and steal a user’s saved credentials with a single click (10 out of 11) including TOTP (9 out of 11). Passkey authentication could also be exploited in some scenarios.”

Following responsible disclosure, six vendors have not yet released fixes for the defects –

1Password Password Manager 8.11.4.27 Apple Icloud Passwords 3.1.25 Bitwarden Password Manager 2025.7.0 Enpass 6.11.6 LastPass 4.146.3 Logmeonce 7.12.4

Identity Security Risk Assessment

Software supply chain security company Socket, which independently reviewed the survey, said that Bitwarden, Enpass and iCloud passwords are actively working on fixing, with 1Password and LastPass markings useful. We are also contacting US-Cert to assign the CVE identifier for the identified issue.

Until the fix is available, users are advised to disable the password manager’s autofill feature and use copy/paste only.

“For Chromium-based browser users, use the extended settings[オン]Click[オン]”We recommend configuring site access to the site,” Tóth said. “This configuration allows users to manually control the autofill feature.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleGoogle doubles AI Phones with Pixel 10 series
Next Article Pixel 10, new Gemini features, Pixel Watch, and everything else announced at the Made by Google 2025 event
user
  • Website

Related Posts

FBI warns FSB-linked hackers exploiting Patchededed Cisco devices for Cyber Spionage

August 20, 2025

Experts have discovered that AI browsers can be tricked by ProsptFix exploits to run malicious hidden prompts

August 20, 2025

Discover and control Shadow AI agents in your company before hackers do it

August 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Smarter Healthcare Starts Now: The Power of Integrated Medical Devices

Google, sorry, that pixel event was Klinge Fest

Pixel 10, new Gemini features, Pixel Watch, and everything else announced at the Made by Google 2025 event

DOM-based extension ClickJacking exposes popular password managers to credentials and data theft

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Smarter Healthcare Starts Now: The Power of Integrated Medical Devices

The Genius of Frustration: Tim Berners-Lee on Creating the Internet We Know

What’s Wrong with the Web? Tim Berners-Lee Speaks Out in Rare Interview

The Next Frontier: NYC Island Becomes Epicenter for Climate Solutions

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.