Search

LastPass Acknowledges New Vulnerability in Browser Extension, Says It's Working on a Fix

Advertisement
Highlights
  • The vulnerabilities were reported by Google researcher Tavis Ormandy
  • LastPass responded to say it's working on a fix
  • Neither Ormandy or LastPass have provided details about the vulnerability
LastPass Acknowledges New Vulnerability in Browser Extension, Says It's Working on a Fix

Internet vulnerabilities are becoming more common with each passing day, and LastPass is no stranger to these. LastPass is a widely used password management service, and just last week, a Google Project Zero researcher named Tavis Ormandy had pointed out several vulnerabilities in the service that were patched up shortly after. Now however, a new vulnerability has come to light, and the password management service says it is working to fix it.

Once again reported by Ormandy, the client-side vulnerability allows for remote code execution (RCE) in the LastPass v4.1.43 extension for Chrome. Ormandy on Sunday shared details with LastPass, which on the same day said it was aware of the issue and asked users to stay tuned for more details.

In a blog post on Monday, LastPass said it is "actively addressing the vulnerability", and that the attack demonstrated by Ormandy was "unique and highly sophisticated." It didn't reveal any further details.

"We don’t want to disclose anything specific about the vulnerability or our fix that could reveal anything to less sophisticated but nefarious parties. So you can expect a more detailed post mortem once this work is complete."

"In the meantime, we want to thank people like Tavis who help us raise the bar for online security with LastPass, and work with our teams to continue to make LastPass the most secure password manager on the market," LastPass wrote in its blog post on Monday.

In the post, LastPass also laid down some best practices for users, including using the LastPass Vault as a launch pad, enabling two-factor authentication on any service that offers it, and to be wary of phishing attacks.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Tecno Pova 7 5G, Pova 7 Pro 5G Launched in India: Price, Availability
  2. Apple Plans to Launch M5-Powered MacBook Pro This Year: Report
  3. YouTube Targets Repetitive Videos in New Monetisation Update
  4. Here's How Much the Vivo X Fold 5 and Vivo X200 FE Might Cost in India
  5. OTT Releases This Week: Kaalidhar Laapata, Thug Life, The Good Wife, and More
  6. The Good Wife OTT Release Date: When and Where to Watch it Online?
  7. iPhone 17 Pro Max Tipped to Get a Battery Upgrade Over Its Predecessor
  8. Paramasivan Fathima OTT Release Date: When and Where to Watch Tamil Horror Thriller Online?
  9. NxtQuantum Arrives as Made in India Mobile OS, to Debut on Its AI+ Phones
  10. Samsung Galaxy Z Fold 7 Hands-On Images Suggest It Might Sport This Design
  1. YouTube to Revise Monetisation Policy to Target Mass-Produced and Repetitive Content
  2. Google Pixel Buds 2a and Pixel Wireless Charger Tipped to Launch Alongside Pixel 10 Series
  3. Telegram Rolls Out Checklists, Suggested Posts and Monetisation Tools in Channels
  4. EA Is Shutting Down BioWare's Anthem Next Year
  5. NxtQuantum Announced as India’s Home-Grown Mobile Operating System, to Debut on AI+ Pulse and Nova 5G
  6. Tecno Pova 7 5G, Pova 7 Pro 5G Launched in India With MediaTek Dimensity 7300 Ultimate SoC
  7. Google Pixel 6a Owners Eligible for $100 Cash or $150 Store Credit Under Battery Performance Programme
  8. Meta AI Chatbots Will Soon Send Users Proactive Follow-Up Messages to Boost Engagement: Report
  9. Android 16’s Live Updates to Show Active Navigation, Ongoing Phone Calls, and More on Lock Screen
  10. Helldivers 2 is Coming to Xbox Series S/X Next Month, Pre-Orders Now Live
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »