Several mobile password managers compromised by AutoSpill vulnerability on Android apps, a vulnerability discovered by researchers at Black Hat Europe 2023. When Android calls a login page via WebView, a credential-stealing flaw emerges, allowing shared credentials to be leaked to the app that requested the login information. Affected password managers include 1Password, LastPass, Enpass, Keeper, and Keepass2Android, along with DashLane and Google Smart Lock if credentials were shared via JavaScript injection. The vulnerability impacts WebView, regardless of the presence of phishing or malicious in-app code. Testing on older devices and Android versions reveals that the flaw may affect outdated hardware and software. However, it emphasizes the importance of keeping Android OS and installed apps up-to-date for overall security. Users should routinely check for OS and app updates to ensure their devices are secure.
Related Posts
Grab the 13-inch MacBook Air M2 for Less Than $1,000 in Best Buy’s Black Friday Sale
- admin
- November 23, 2023
- 0
This 13.6-inch MacBook Air is currently on sale for $950 at Best Buy, a $150 discount from its original price. ZDNET recommends this deal because […]
Exciting News: Apple Set to Release Two OLED iPad Pros and 12.9-inch Air in Early 2024
- admin
- November 14, 2023
- 0
The forecast for Apple’s iPad lineup in 2024 is ambitious, according to Ming-Chi Kuo. The iPad Pro, iPad Air, iPad Mini, and regular iPad are […]
Test Your Skill: Can You Detect a Fake AI-Generated News Story?
- admin
- December 2, 2023
- 0
A recent survey by cybersecurity provider Netskope has revealed that a lot of people struggle to distinguish between real news stories and those generated by […]