Search

LastPass Issues Fix for Critical Bug That Could Expose Password Credentials

Users are advised to update to LastPass version 4.33.0 as soon as possible.

Advertisement
Highlights
  • All LastPass users must update to the latest version
  • LastPass bug was reported by Google’s Tavis Ormandy
  • The bug report was published recently by Google
LastPass Issues Fix for Critical Bug That Could Expose Password Credentials

LastPass has issued a new important bug fix

Password-manager LastPass has fixed a critical bug that could have been used to leak last used credentials. The bug was discovered last month, and a bug report has now been published for the public. The report published by Tavis Ormandy, a security researcher with Project Zero, Google's security and bug-hunting team, pegs the bug to be ‘highly severe' and potentially exploitable. Because the report details the necessary steps to reproduce the vulnerability, it is important that all users update to version 4.33.0. LastPass issued a fix for the bug with this new version last week.

As mentioned, the password manager's vulnerability was discovered by Ormandy and privately reported to the company last month. LastPass issued an update last week, and now Google has made the bug report public. It details a step by step process by which the bug can be reproduced and misused, and the report can be found on the company site. The flaw in the browser extension of its password manager software created a clickjacking risk. It essentially produced a way for malicious sites to trick LastPass users into disclosing the credentials of a site they had previously visited. Ormandy tweeted that LastPass could leak the last used credentials due to a cache not being updated.

In its defence, LastPass issued an advisory. “To exploit this bug, a series of actions would need to be taken by a LastPass user including filling a password with the LastPass icon, then visiting a compromised or malicious site and finally being tricked into clicking on the page several times. This exploit may result in the last site credentials filled by LastPass to be exposed. We quickly worked to develop a fix and verified the solution was comprehensive with Tavis,” the post explained.

The company further says that no user action is required and your LastPass browser extension will update automatically. However, we do recommend all users to double check if they are on the latest update version 4.33.0, to be absolutely sure they are safe from any potential threats. These developments were first reported by ZDNet.

As the bug was discovered in private and fixed, there's no reason to believe that it may have been exploited in the wild or misused. In any event, we do not recommend against using password managers. They enable users to have unique passwords for different websites, and are critical tools for staying safe because the most annoying thing about the internet is passwords, and remembering them. However, we do recommend keeping a regular check on software updates, and staying up-to-date on that front.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: LastPass
 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo T4R 5G to Launch Soon in India; Design Teased
  2. Realme 15 Pro 5G to Get 50-Megapixel Sony IMX896 Main Rear Camera
  3. Samsung Galaxy F36 5G India Launch Date Announced; Design Shown
  4. Motorola Razr 60 Ultra Review: Flip Phone Perfection?
  5. iQOO Z10R With 32-Megapixel Selfie Camera to Launch in India on This Date
  6. Here's When Apple Could Unveil the iPhone 17 Series
  7. HMD T21 Tablet With 10.36-Inch 2K Display Launched in India: Check Price
  8. Grok Will Now Let You Chat With a Goth Anime Girl That Has an NSFW Mode
  1. Samsung Developing New Technologies to Bring Back S-Pen in Future Galaxy Z Fold Models: Report
  2. Cyberpunk 2077: Ultimate Edition Coming to Apple Silicon-Powered Mac on July 17
  3. Axiom Space’s Ax-4 Crew Returns from ISS Aboard SpaceX Dragon Grace After Record Research Mission
  4. Crystalline Ice Discovered in Space: New Study Reveals Hidden Order in Cosmic Ice
  5. NASA Deploys High-Tech Aircraft to Support Texas Flood Relief and Recovery Efforts
  6. Massive Boulders Ejected by DART Mission Could Complicate Future Asteroid Deflection
  7. The Map That Leads to You OTT Release Date: When and Where to Watch it Online?
  8. Anuraga Karikkim Vellam Streaming Now on SunNXT: Everything To Know About Cast, Plot, and More
  9. CyberPowerPC India Announces Launch of Esports Masterclass Series in Navi Mumbai
  10. iPhone 16 Available at Rs 69,999 in Flipkart's GOAT Sale 2025; Price Discounted on Amazon as Well
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »