LastPass Acknowledges New Vulnerability in Browser Extension, Says It's Working on a Fix

Advertisement
By Shubham Verma | Updated: 28 March 2017 20:23 IST
Highlights
  • The vulnerabilities were reported by Google researcher Tavis Ormandy
  • LastPass responded to say it's working on a fix
  • Neither Ormandy or LastPass have provided details about the vulnerability

Internet vulnerabilities are becoming more common with each passing day, and LastPass is no stranger to these. LastPass is a widely used password management service, and just last week, a Google Project Zero researcher named Tavis Ormandy had pointed out several vulnerabilities in the service that were patched up shortly after. Now however, a new vulnerability has come to light, and the password management service says it is working to fix it.

Once again reported by Ormandy, the client-side vulnerability allows for remote code execution (RCE) in the LastPass v4.1.43 extension for Chrome. Ormandy on Sunday shared details with LastPass, which on the same day said it was aware of the issue and asked users to stay tuned for more details.

In a blog post on Monday, LastPass said it is "actively addressing the vulnerability", and that the attack demonstrated by Ormandy was "unique and highly sophisticated." It didn't reveal any further details.

Advertisement

"We don’t want to disclose anything specific about the vulnerability or our fix that could reveal anything to less sophisticated but nefarious parties. So you can expect a more detailed post mortem once this work is complete."

Advertisement

"In the meantime, we want to thank people like Tavis who help us raise the bar for online security with LastPass, and work with our teams to continue to make LastPass the most secure password manager on the market," LastPass wrote in its blog post on Monday.

In the post, LastPass also laid down some best practices for users, including using the LastPass Vault as a launch pad, enabling two-factor authentication on any service that offers it, and to be wary of phishing attacks.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. MacBook Air (2025) With M4 Chip Available at This Discounted Price
  2. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  3. Motorola Edge 70 With 5,000mAh Battery Launched in India at This Price
  4. Oppo Reno 15c With Snapdragon 7 Gen 4 SoC Launched at This Price
  5. Logitech MX Master 4 Launches in India With These Features
  6. Jio Launches Happy New Year 2026 Prepaid Plans: Check Price, Benefits
  7. ChatGPT's Adult Mode Might Arrive in Early 2026
  8. Samsung Might Build 2nm Process Chipsets for AMD
  9. Samsung Galaxy A Series to Get More Expensive in India Soon, Tipster Claims
  1. Clair Obscur: Expedition 33 Gets New 'Thank You' Update After Winning at The Game Awards
  2. Apple Fitness+ Now Available in India With Custom Workout Programmes: Price and Other Details
  3. Samsung Could Reportedly Strike a Deal With AMD to Build Future 2nm Process Chipsets
  4. Pixel 10 Series, Pixel Accessories Get Price Cuts in India During Google's End of Year Sale
  5. Alexa's Popular Requests in 2025 Included K-Pop, Bollywood, Podcasts and Details About Celebrities
  6. Logitech MX Master 4 Launched in India With 8,000 DPI Sensor and Multi-Pairing Support
  7. Amazon Introduces Ask This Book AI Feature for the Kindle App, Provides Spoiler-Free Answers
  8. MacBook Air (2025) With M4 Chip Available With Over Rs. 10,000 Discount in India: Here Are the Details
  9. Oppo Reno 15c Launched With Snapdragon 7 Gen 4 SoC, 6,500mAh Battery: Price, Specifications
  10. Star Wars: Fate of the Old Republic Will Launch Before 2030, Game Director Confirms
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.