ADVERTISEMENT

Major flaw affecting password managers: they autofill credentials for attackers

A major flaw is affecting major password managers – attackers can steal credit card details and credentials from tens of millions of users with just “a single click anywhere.” 1Password, Bitwarden, Dashlane, Enpass, iCloud Passwords, Keeper, LastPass, LogMeOnce, NordPass, ProtonPass, and RoboForm – all failed, and many remain vulnerable.

passwords

Image by Cybernews.

Ernestas Naprys
Ernestas Naprys Senior Journalist
August 21, 2025 Updated: August 25, 2025 6 min read
Key takeaways:
Has my data been leaked?

How can hackers steal passwords unnoticed?

passwords
Image by Cybernews
  • Setting the opacity to 0 will allow only the elements behind it to be displayed, such as cookie consent banners or CAPTCHA, with button placements matched.
  • The form can be partially overlaid with other intrusive UI elements without changing its opacity. The user will be forced to click the small uncovered area.
  • A full overlay can be used, covering the entire form. It would normally not be clickable, but attackers can bypass this by using “pointer-events:none,” which makes the overlay ignore mouse actions and enables clicks to pass through to underlying elements.

Which password managers fail?

vulnerable-password-managers1
Image by Marek Tóth.
ADVERTISEMENT
vulnerable-password-managers
Image by Marek Tóth.
vulnerable-password-managers3
Image by Marek Tóth.

Mitigations are bypassable

What can you do to be safe?

ADVERTISEMENT