logo

Clickjack attack steals password managers’ secrets

ID: 0502fee0-133e-54e3-b25c-f9f9c9f2213c

STIX ID: report--0502fee0-133e-54e3-b25c-f9f9c9f2213c

Feed Name: Malwarebytes Blog

Threat Score
60/100

Date Published: 2025-08-22

Date Updated: 2026-04-28

...
...

A researcher demonstrated a DOM-based clickjacking attack that can trick extension-based password managers into autofilling and exposing credentials, payment data, passkeys and TOTP codes; several vendors have partially or fully patched the issue while others are still working on fixes. Recommended mitigations include disabling autofill, restricting extension site access to "on click", and keeping password manager extensions up to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.