Clickjack attack steals password managers’ secrets
ID: 0502fee0-133e-54e3-b25c-f9f9c9f2213c
STIX ID: report--0502fee0-133e-54e3-b25c-f9f9c9f2213c
Feed Name: Malwarebytes Blog
Threat Score
A researcher demonstrated a DOM-based clickjacking attack that can trick extension-based password managers into autofilling and exposing credentials, payment data, passkeys and TOTP codes; several vendors have partially or fully patched the issue while others are still working on fixes. Recommended mitigations include disabling autofill, restricting extension site access to "on click", and keeping password manager extensions up to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
