Several mobile password managers compromised by AutoSpill vulnerability on Android apps, a vulnerability discovered by researchers at Black Hat Europe 2023. When Android calls a login page via WebView, a credential-stealing flaw emerges, allowing shared credentials to be leaked to the app that requested the login information. Affected password managers include 1Password, LastPass, Enpass, Keeper, and Keepass2Android, along with DashLane and Google Smart Lock if credentials were shared via JavaScript injection. The vulnerability impacts WebView, regardless of the presence of phishing or malicious in-app code. Testing on older devices and Android versions reveals that the flaw may affect outdated hardware and software. However, it emphasizes the importance of keeping Android OS and installed apps up-to-date for overall security. Users should routinely check for OS and app updates to ensure their devices are secure.
Related Posts
Optimizing Your Pixel Buds Pro Sound with Pixel Phone Settings: A Guide
- admin
- November 29, 2023
- 0
The Denon PerL Pro earbuds are my baseline for optimal sound in earbuds, but the Pixel Buds Pro are also great. A small adjustment gets […]
Score $200 Off the iPhone 15 Pro Max at Best Buy’s Cyber Monday Sale
- admin
- November 29, 2023
- 0
Apple’s iPhone 15 Pro Max is on sale at Best Buy for $200 off on Cyber Monday, bringing the price down to $999. This deal […]
Maximizing Efficiency: Installing DNF5 on Fedora 39 for Swift Application Installation and Management
- admin
- November 13, 2023
- 0
DNF5 vastly improves the experience and performance of Fedora Linux. It replaces the aging original Linux package manager with a faster package that features a […]