LastPass Issues Fix for Critical Bug That Could Expose Password Credentials

Users are advised to update to LastPass version 4.33.0 as soon as possible.

Advertisement
By Tasneem Akolawala | Updated: 16 September 2019 18:51 IST
Highlights
  • All LastPass users must update to the latest version
  • LastPass bug was reported by Google’s Tavis Ormandy
  • The bug report was published recently by Google

LastPass has issued a new important bug fix

Password-manager LastPass has fixed a critical bug that could have been used to leak last used credentials. The bug was discovered last month, and a bug report has now been published for the public. The report published by Tavis Ormandy, a security researcher with Project Zero, Google's security and bug-hunting team, pegs the bug to be ‘highly severe' and potentially exploitable. Because the report details the necessary steps to reproduce the vulnerability, it is important that all users update to version 4.33.0. LastPass issued a fix for the bug with this new version last week.

As mentioned, the password manager's vulnerability was discovered by Ormandy and privately reported to the company last month. LastPass issued an update last week, and now Google has made the bug report public. It details a step by step process by which the bug can be reproduced and misused, and the report can be found on the company site. The flaw in the browser extension of its password manager software created a clickjacking risk. It essentially produced a way for malicious sites to trick LastPass users into disclosing the credentials of a site they had previously visited. Ormandy tweeted that LastPass could leak the last used credentials due to a cache not being updated.

Advertisement

In its defence, LastPass issued an advisory. “To exploit this bug, a series of actions would need to be taken by a LastPass user including filling a password with the LastPass icon, then visiting a compromised or malicious site and finally being tricked into clicking on the page several times. This exploit may result in the last site credentials filled by LastPass to be exposed. We quickly worked to develop a fix and verified the solution was comprehensive with Tavis,” the post explained.

The company further says that no user action is required and your LastPass browser extension will update automatically. However, we do recommend all users to double check if they are on the latest update version 4.33.0, to be absolutely sure they are safe from any potential threats. These developments were first reported by ZDNet.

Advertisement

As the bug was discovered in private and fixed, there's no reason to believe that it may have been exploited in the wild or misused. In any event, we do not recommend against using password managers. They enable users to have unique passwords for different websites, and are critical tools for staying safe because the most annoying thing about the internet is passwords, and remembering them. However, we do recommend keeping a regular check on software updates, and staying up-to-date on that front.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: LastPass
Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Turbo 5 Confirmed to Launch in India With This Rear Camera Setup
  2. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  3. OnePlus Turbo 6X Series Will Launch in China on This Date
  4. WhatsApp Users on iOS Are Finally Getting Access to This Useful Feature
  5. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  6. How Asus is Rewriting the Rules of Laptop Design From the Inside Out
  7. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  8. How to Watch WWDC 2026 Live on YouTube, Apple TV, and More
  9. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  10. Ginny Wedss Sunny 2 OTT Release: A New Chapter of Love, Laughter, and Family Chaos
  1. Samsung Galaxy S26 FE Said to Ditch Matte Finish for a Glossy Rear Panel
  2. OnePlus N Series Tipped to Launch in India Next Month, Could Be More Affordable Than the OnePlus Nord CE 6 Lite
  3. Vivo Y31s 5G Launched With Snapdragon 4 Gen 2 Chip, 6,500mAh Battery: Price, Specifications
  4. Chinese Court Classifies Bitcoin as Property in Case Involving 107 BTC Theft
  5. Resident Evil Veronica Revealed at Summer Game Fest; Launch Set for 2027
  6. iQOO Neo 12 Said to Bring Major Display Upgrade With Up to 185Hz Refresh Rate
  7. Samsung Galaxy Watch Ultra 2, Galaxy Watch 9 Clear Key Regulatory Hurdle Ahead of Anticipated Launch
  8. Microsoft Reportedly Working on Shared Audio Feature on Windows 11 Alongside Tweaked Widgets
  9. WhatsApp Multi-Account Support on iOS Reportedly Rolling Out to More Users
  10. HTX Delists USD1 Stablecoin, Asks World Liberty Financial to Reverse Freeze on Exchange's Addresses
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.