Global security desk · updated coverage of threats, exploits & breaches

Password Manager Vulnerability Lets Attackers Seize User Accounts

Researchers have disclosed a serious weakness inside one of the most widely used consumer password managers, a flaw that could let a remote attacker walk away with every credential stored in a victim's vault. The issue, reported privately to the vendor several weeks ago and patched in a quiet update this week, affects the software's browser extension and the way it negotiates identity with the websites a person visits. Independent testers say a single malicious page is enough to trigger the chain, and they warn that any account protected by the affected tool should be considered exposed until mitigations are applied.

The timing is awkward. Australians keep a growing share of their finances, superannuation, tax records and work logins inside password managers, and the same tools often hold the keys to myGov, the ATO, the big four banks, and a long list of customer portals. A vulnerability that turns a password manager from a security helper into a single point of failure is the kind of issue that makes the Australian Cyber Security Centre sit up straight, and it lands just as local IT teams are already stretched by a long run of cloud and identity-related incidents. Coverage of related credential exposure appears across earlier reporting, with the data-breach-at-major-cloud-provider-exposes-customer-secrets case showing how quickly stolen secrets travel once they leave a vault.

How the flaw was found

The bug was uncovered by a small group of independent researchers who had been auditing browser extensions for ways they could be coerced into revealing stored material. They noticed that the extension's content script, the small program injected into every page, did not properly check the origin of the document it was running in. A crafted subdomain, served from a domain the extension treated as trusted, was enough to slip past the same-origin checks and to read data that should have stayed locked inside the extension's protected storage.

That sounds technical, but the practical effect is grim. Once the script ran in the malicious context, it could ask the extension to fill credentials for a target site, capture what was returned, and forward it to an attacker-controlled server. In a follow-on step, the same script could request the active session token, the small piece of data that tells a website the visitor is already logged in. With both a username and password and a live session, the attacker does not need to log in at all; they simply resume the victim's session from their own browser and the account is theirs.

The researchers coordinated disclosure through a recognised vulnerability programme and gave the vendor a standard 90-day window before going public. Patches were prepared in parallel, and the public write-up, which dropped on the same day as the release, walked readers through the proof of concept without including ready-to-run exploit code. That balance has become the norm in modern vulnerability reporting, and it tends to keep the window of mass exploitation short, though it never closes it entirely.

What the attack chain looks like in practice

Picture a typical weekday in a Sydney or Melbourne office. A staff member opens a browser tab, clicks a link in what looks like a normal newsletter, and lands on a page that looks like a generic blog. Behind the scenes, that page has a specially constructed subdomain that the password manager treats as part of its own trusted universe. The extension's content script wakes up, the malicious page issues a series of internal requests, and within seconds the script has harvested the credentials stored for several high-value sites, including a corporate single sign-on portal.

From there, the attacker moves to the stolen session. Many modern web applications issue session tokens that can last for hours or even days, particularly when "remember me" boxes are ticked. The researcher team found that the extension's session handling exposed those tokens to the same script that harvested passwords, which means an attacker does not need to defeat multi-factor authentication immediately. They can replay the active session, change the account recovery options, lock the real user out, and only later deal with the second factor when conditions are quieter.

This is the pattern that worries Australian defenders most. The Notifiable Data Breaches scheme, run through the Office of the Australian Information Commissioner, expects organisations to report incidents where credential exposure is likely to lead to serious harm. A compromised password manager can produce that outcome for many accounts at once, and the work of working out what to tell the OAIC often begins before the IT team has finished wiping the affected endpoints. For a closer look at how attackers turn stolen credentials into operational impact, the Dharma ransomware analysis walks through the kind of follow-on intrusion that follows once a foothold is established.

Who is affected and how broadly

The vendor has confirmed the vulnerability affected the desktop browser extension on Chromium-based browsers, including the versions most Australians use at home and at work. Mobile apps, standalone desktop applications and the command-line companion were not impacted by the same flaw, although the company has used the disclosure to harden related code paths in those products as well. The number of installations runs into the tens of millions worldwide, and the vendor's own telemetry suggests a meaningful slice of those sit on Australian machines, where the product has been bundled with several internet service providers over the years.

Enterprise customers are not insulated simply because they pay for the premium tier. The extension is the same binary in both consumer and business builds, and the same content script runs regardless of the licence. The difference is mainly in policy, and many corporate deployments had not yet enforced the new "only fill on confirmed top-level domain" setting when the patch shipped. That gap is what IT managers are scrambling to close, because without it, a single staff member visiting a hostile site can undermine the rest of the organisation's identity controls.

Smaller businesses and sole traders face a rougher version of the same problem. They rarely have a security operations centre watching the extension's behaviour, and they often reuse the same vault for personal and work accounts. A breach of one often means exposure of the other, and the path from a personal Facebook takeover to a compromised business email inbox is short and well rehearsed by criminal groups operating on dark-web marketplaces.

The vendor's response and the patch

The vendor published a security advisory on the same day the researchers released their write-up, an unusually tight turnaround that reflects how seriously the report was taken internally. The fix lives in the extension's content script and tightens the way it decides which origins are allowed to interact with stored items. Users who have automatic updates enabled will already have the patch, and the company has confirmed that no exploit chain requires user interaction beyond visiting a web page, which is why the urgency around the update is so high.

Independent reviewers have signed off on the fix, and a second round of regression testing is underway to make sure the new origin checks do not break legitimate autofill behaviour. The vendor has also rotated internal signing keys and pushed a new policy template that lets administrators force the safer configuration on managed devices. Customers who self-host the credential synchronisation service have been given a short window to apply the same change on their own infrastructure, with detailed instructions in the advisory's technical appendix.

The episode has drawn attention from regulators and from groups that track software supply chain risk. The Australian Cyber Security Centre's guidance on password manager hygiene, last refreshed in 2023, already warned that the tools are a high-value target, and the centre is expected to update its advice for both government agencies and critical infrastructure operators. For context on the wider pattern of credential-focused incidents, the 2018/01 archive documents how identity attacks have evolved, and it makes plain that the current disclosure is part of a long, slow campaign rather than a one-off.

What users and IT teams should do now

For everyday Australians, the first step is the dull but essential one: make sure the extension has updated. The version number is visible in the extension's settings page, and the vendor has published a specific build that contains the fix. Once updated, it is worth opening the vault and reviewing the entries for the highest-value accounts, particularly the ones tied to banking, superannuation, myGov and any email account used for password recovery. Anything that looks unfamiliar or that has been filled recently on a page you do not remember visiting should be treated as suspect and the password rotated immediately.

Multi-factor authentication remains the most effective safety net when credentials do leak, but the way it is configured matters. App-based codes and hardware security keys, including the FIDO2 tokens now supported by most major Australian banks, are far harder to defeat in a session-replay scenario than SMS one-time passwords. Where possible, the second factor should be required at every login rather than only on new devices, because the attacker in this kind of attack chain is effectively using a new device even when they are reusing a stolen session.

For IT and security teams, the work is heavier. The patched extension should be pushed to every managed browser as a priority, and the safer autofill policy should be turned on through the management console. Conditional access rules should be reviewed so that a session token replayed from an unexpected country or device is challenged or blocked, and audit logs should be searched for any sign of the kind of malicious subdomain requests that powered the attack. Finally, the incident is a useful prompt to revisit the organisation's broader password manager strategy, including the question of whether the same tool should be holding both personal and corporate credentials, and whether the recovery flow for the master password itself is strong enough to resist a targeted attempt to seize the whole vault.