• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

DOM-Primarily based Extension Clickjacking Exposes Fashionable Password Managers to Credential and Information Theft

Admin by Admin
August 20, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Aug 20, 2025Ravie LakshmananVulnerability / Browser Safety

Fashionable password supervisor plugins for net browsers have been discovered prone to clickjacking safety vulnerabilities that might be exploited to steal account credentials, two-factor authentication (2FA) codes, and bank card particulars underneath sure circumstances.

The approach has been dubbed Doc Object Mannequin (DOM)-based extension clickjacking by impartial safety researcher Marek Tóth, who introduced the findings on the DEF CON 33 safety convention earlier this month.

“A single click on wherever on an attacker-controlled web site may permit attackers to steal customers’ knowledge (bank card particulars, private knowledge, login credentials, together with TOTP),” Tóth stated. “The brand new approach is basic and may be utilized to different kinds of extensions.”

Cybersecurity

Clickjacking, additionally known as UI redressing, refers to a sort of assault through which customers are tricked into performing a collection of actions on a web site that seem ostensibly innocent, resembling clicking on buttons, when, in actuality, they’re inadvertently finishing up the attacker’s bidding.

The brand new approach detailed by Tóth basically includes utilizing a malicious script to control UI parts in an internet web page that browser extensions inject into the DOM — for instance, auto-fill prompts, by making them invisible by setting their opacity to zero.

The analysis particularly centered on 11 standard password supervisor browser add-ons, starting from 1Password to iCloud Passwords, all of which have been discovered to be prone to DOM-based extension clickjacking. Collectively, these extensions have tens of millions of customers.

To tug off the assault, all a nasty actor has to do is create a faux website with an intrusive pop-up, resembling a login display screen or a cookie consent banner, whereas embedding an invisible login kind such that clicking on the positioning to shut the pop-up causes the credential info to be auto-filled by the password supervisor and exfiltrated to a distant server.

“All password managers crammed credentials not solely to the ‘predominant’ area, but additionally to all subdomains,” Tóth defined. “An attacker may simply discover XSS or different vulnerabilities and steal the person’s saved credentials with a single click on (10 out of 11), together with TOTP (9 out of 11). In some situations, passkey authentication may be exploited (8 out of 11).”

Following accountable disclosure, six of the distributors have but to launch fixes for the defect –

  • 1Password Password Supervisor 8.11.4.27
  • Apple iCloud Passwords 3.1.25
  • Bitwarden Password Supervisor 2025.7.0
  • Enpass 6.11.6
  • LastPass 4.146.3
  • LogMeOnce 7.12.4
Identity Security Risk Assessment

Software program provide chain safety agency Socket, which independently reviewed the analysis, stated Bitwarden, Enpass, and iCloud Passwords are actively engaged on fixes, whereas 1Password and LastPass marked them as informative. It has additionally reached out to US-CERT to assign CVE identifiers for the recognized points.

Till fixes can be found, it is suggested that customers disable the auto-fill operate of their password managers and solely use copy/paste.

“For Chromium-based browser customers, it’s endorsed to configure website entry to ‘on click on’ in extension settings,” Tóth stated. “This configuration permits customers to manually management auto-fill performance.”

Tags: ClickjackingCredentialDataDOMBasedexposesextensionManagersPasswordPopularTheft
Admin

Admin

Next Post
Resident Evil Requiem Mode Lets Devs Select The Digital camera

Resident Evil Requiem Mode Lets Devs Select The Digital camera

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Why Longer Content material Is not Higher

Why Longer Content material Is not Higher

April 23, 2025
A Complete Information • AI Weblog

A Complete Information • AI Weblog

May 11, 2025

Trending.

New Win-DDoS Flaws Let Attackers Flip Public Area Controllers into DDoS Botnet through RPC, LDAP

New Win-DDoS Flaws Let Attackers Flip Public Area Controllers into DDoS Botnet through RPC, LDAP

August 11, 2025
Microsoft Launched VibeVoice-1.5B: An Open-Supply Textual content-to-Speech Mannequin that may Synthesize as much as 90 Minutes of Speech with 4 Distinct Audio system

Microsoft Launched VibeVoice-1.5B: An Open-Supply Textual content-to-Speech Mannequin that may Synthesize as much as 90 Minutes of Speech with 4 Distinct Audio system

August 25, 2025
Stealth Syscall Method Permits Hackers to Evade Occasion Tracing and EDR Detection

Stealth Syscall Method Permits Hackers to Evade Occasion Tracing and EDR Detection

June 2, 2025
The place is your N + 1?

Work ethic vs self-discipline | Seth’s Weblog

April 21, 2025
Qilin Ransomware Makes use of TPwSav.sys Driver to Bypass EDR Safety Measures

Qilin Ransomware Makes use of TPwSav.sys Driver to Bypass EDR Safety Measures

July 31, 2025

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Black Ops 7 u-turns on Black Ops 6 Carry Ahead simply days after asserting it due to the huge backlash

Black Ops 7 u-turns on Black Ops 6 Carry Ahead simply days after asserting it due to the huge backlash

August 28, 2025
Don’t let “again to high school” turn into “again to bullying”

Don’t let “again to high school” turn into “again to bullying”

August 28, 2025
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved