Password manager flaw exposed vaults in a single click
Researchers demonstrated a chain of three bugs that dumped stored credentials without cracking the master password. A patch is already out.
Original: SecurityLab
Researchers at an independent lab published a teardown of a flaw that let a browser password-manager extension dump a user’s entire vault. No master password was ever cracked — visiting a crafted page was enough.
What actually broke
The chain had three links, and each one looked harmless in isolation:
- The extension injected its script into pages under a far broader rule than it needed.
- That script accepted commands from the page’s own window without checking who sent them.
- An internal handler trusted those commands and returned decrypted records.
Remove any single link and the attack falls apart. That is precisely why findings like this survive for years: every piece passes review on its own.
What it looked like to the user
Nothing. You open an ordinary page, read the text — meanwhile the extension has already handed over a list of logins and passwords. No dialogs, no warnings, no permission prompts.
The nastiest part of this story is the total absence of symptoms. A user cannot suspect an attack when there is nothing to notice.
What to do
The patch landed on Tuesday and is worth applying immediately — extensions usually update themselves, but check the version by hand. If the manager syncs its vault across devices, treat anything saved before the update as compromised and rotate at least the credentials tied to email and banking.
Why it matters
Password managers are one of the few tools where users deliberately put everything into a single basket. Their safety rests not on cryptography but on care in the small places: script injection rules, message-origin checks, privilege separation. This time it was the care that failed.