Update now to fix flaw in every password manager
Bitwarden is one of several password managers to have released emergency updates for their browser extensions to fix a severe flaw that hackers can exploit to steal passwords, two-factor authentication codes and payment-card details.
WHAT WE THINK
Clickjacking has been a threat for over 20 years, but this is the first time researchers have shown how cybercriminals could use it to hack the autofill tool of password managers. Thankfully, there’s no evidence they’ve actually done this, and password managers have responded quickly to fix the flaw. But it does highlight the inherent dangers behind autofill – and the constant trade-off between convenience and security. Copying and pasting your details takes longer but is much safer.