LastPass Acknowledges New Vulnerability in Browser Extension, Says It's Working on a Fix

Advertisement
By Shubham Verma | Updated: 28 March 2017 20:23 IST
Highlights
  • The vulnerabilities were reported by Google researcher Tavis Ormandy
  • LastPass responded to say it's working on a fix
  • Neither Ormandy or LastPass have provided details about the vulnerability

Internet vulnerabilities are becoming more common with each passing day, and LastPass is no stranger to these. LastPass is a widely used password management service, and just last week, a Google Project Zero researcher named Tavis Ormandy had pointed out several vulnerabilities in the service that were patched up shortly after. Now however, a new vulnerability has come to light, and the password management service says it is working to fix it.

Once again reported by Ormandy, the client-side vulnerability allows for remote code execution (RCE) in the LastPass v4.1.43 extension for Chrome. Ormandy on Sunday shared details with LastPass, which on the same day said it was aware of the issue and asked users to stay tuned for more details.

Advertisement

In a blog post on Monday, LastPass said it is "actively addressing the vulnerability", and that the attack demonstrated by Ormandy was "unique and highly sophisticated." It didn't reveal any further details.

"We don’t want to disclose anything specific about the vulnerability or our fix that could reveal anything to less sophisticated but nefarious parties. So you can expect a more detailed post mortem once this work is complete."

Advertisement

"In the meantime, we want to thank people like Tavis who help us raise the bar for online security with LastPass, and work with our teams to continue to make LastPass the most secure password manager on the market," LastPass wrote in its blog post on Monday.

In the post, LastPass also laid down some best practices for users, including using the LastPass Vault as a launch pad, enabling two-factor authentication on any service that offers it, and to be wary of phishing attacks.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Turbo 5 Confirmed to Launch in India With This Rear Camera Setup
  2. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  3. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  4. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  5. WhatsApp Users on iOS Are Finally Getting Access to This Useful Feature
  6. Vivo Y31s Launched in Malaysia With These Features
  7. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  8. Infinix Smart 20 Launched in India With a 7.7mm Slim Body, Ultra Link Support
  9. Samsung Galaxy A27 Spotted in Leaked Mint Colourway, Might Launch Soon
  10. Samsung Galaxy Watch Ultra 2, Watch 9 Visit China's 3C Ahead of Launch
  1. Samsung Galaxy S26 FE Said to Ditch Matte Finish for a Glossy Rear Panel
  2. Vivo Y31s 5G Launched With Snapdragon 4 Gen 2 Chip, 6,500mAh Battery: Price, Specifications
  3. Chinese Court Classifies Bitcoin as Property in Case Involving 107 BTC Theft
  4. Resident Evil Veronica Revealed at Summer Game Fest; Launch Set for 2027
  5. iQOO Neo 12 Said to Bring Major Display Upgrade With Up to 185Hz Refresh Rate
  6. Samsung Galaxy Watch Ultra 2, Galaxy Watch 9 Clear Key Regulatory Hurdle Ahead of Anticipated Launch
  7. Microsoft Reportedly Working on Shared Audio Feature on Windows 11 Alongside Tweaked Widgets
  8. WhatsApp Multi-Account Support on iOS Reportedly Rolling Out to More Users
  9. HTX Delists USD1 Stablecoin, Asks World Liberty Financial to Reverse Freeze on Exchange's Addresses
  10. Asus Dawn 7 Pro Series Launched With Up to 16-Inch 144Hz Display, AMD Ryzen AI 7 445 Chip: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.