Multiple top password managers vulnerable to password stealing clickjacking attacks – here’s what we know



  • Multiple password managers are suceptible to a new attack
  • The attack abuses opacity settings and autofill capabilities
  • Passwords, 2FA codes, and credit card details can be stolen

At the recent DEF CON 33 conference, independent researcher Marek Tóth unveiled a clickjacking attack he claims could exploit the autofill capabilities of six of the biggest password managers.

The attack is able to steal passwords, 2FA codes, and credit card details, making it a serious concern for tens of millions of password manager users.

https://cdn.mos.cms.futurecdn.net/ZZhh5oCYXyNNbqdNuJeSJa.jpg



Source link
benedict.collins@futurenet.com (Benedict Collins)

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img