Password manager LastPass creates a workaround for a serious vulnerability affecting browser extensions in Chrome, Firefox, and Microsoft Edge.
Password manager LastPass has fixed a serious vulnerability in its browser extensions for Google Chrome, Mozilla Firefox, and Microsoft Edge. The flaw was discovered by Google's Tavis Ormandy, reports Network World. It could have been exploited to access extensions' internal commands and steal passwords or personal information.
LastPass has put a workaround in place to provide protection from malicious codes and plans to fully fix the flaw in updated versions.
Ormandy later reported another vulnerability in the Firefox extension, which LastPass said was linked to the first. The problem was immediately fixed in a new version of the extension 4.1.36a released the next day.
"No password changes are required of users at this time," say LastPass developers.
Read details on Network World.
About the Author(s)
You May Also Like
Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024Where and Why Threat Intelligence Makes Sense for Your Enterprise Security Strategy
May 15, 2024Safeguarding Political Campaigns: Defending Against Mass Phishing Attacks
May 16, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024