If you use this password manager, you could be at risk | Digital Trends (2024)

Researchers have just found a flaw within Bitwarden, a popular password manager. If exploited, the bug could give hackers access to login credentials, compromising various accounts.

The flaw within Bitwarden was spotted by Flashpoint, a security analysis firm. While the issue hasn’t received much — or any — coverage in the past, it appears that Bitwarden was aware of it all along. Here’s how it works.

If you use this password manager, you could be at risk | Digital Trends (1)

The potential security risk lies within Bitwarden’s autofill on page load feature. It lets inline frames (iframes) access your login details, and if said iframes are compromised, then so are your credentials. An iframe is an HTML element that allows developers to embed a different webpage within the page you’re currently on. They’re often used for the purpose of embedding ads, videos, or web analytics.

According to Flashpoint, using Bitwarden with autofill enabled on a page that contains iframes could result in password theft. This is because autofill on page load automatically fills out your login and password both on the page you’re on and within the iframe — and that exposes you to certain risks.

In its report, Flashpoint said: “While the embedded iframe does not have access to any content in the parent page, it can wait for input to the login form and forward the entered credentials to a remote server without further user interaction.”

There’s another way hackers could steal your passwords, though. Bitwarden’s autofill on page load also works on subdomains of the domain you’re trying to access, as long as the login matches. This means that if you stumble upon a phishing page, with a subdomain that matches the base domain you’ve saved your password for, Bitwarden might automatically provide it to the hacker.

“Some content hosting providers allow hosting arbitrary content under a subdomain of their official domain, which also serves their login page. As an example, should a company have a login page at https://logins.company.tld and allow users to serve content under https://<clientname>.company.tld, these users are able to steal credentials from the Bitwarden extensions,” Flashpoint explained.

If you use this password manager, you could be at risk | Digital Trends (2)

This problem won’t crop up on legitimate, large websites, but free hosting services allow for such domains to be made. Still, both flaws have a pretty small chance of occurring, which is why Bitwarden hasn’t fixed the issue despite being aware of it. In order to keep working on websites that use iframes, Bitwarden has to leave this window of opportunity open for possible phishing and password theft.

It’s worth noting that autofill on page load is disabled in Bitwarden by default, and the tool does warn users about the possible risks when they turn the feature on. In response to the report, Bitwarden has said it’s planning an update that will block autofill on subdomains.

If you’re not using a tool like Bitwarden yet, make sure to check out our guide to the best password managers. Bitwarden is on that list, and despite this security flaw, it still deserves its place — but perhaps disabling autofill on page load might be a good idea for the time being.

If you use this password manager, you could be at risk | Digital Trends (2024)
Top Articles
SEC Rule 17a-3 & FINRA Records Retention Requirements Explained
Can You Do an In-Kind Transfer Into an IRA? | The Motley Fool
Calvert Er Wait Time
Durr Burger Inflatable
Canya 7 Drawer Dresser
Fredatmcd.read.inkling.com
Napa Autocare Locator
Celebrity Extra
PRISMA Technik 7-10 Baden-Württemberg
Wmu Course Offerings
Www.craigslist Augusta Ga
Gore Videos Uncensored
DENVER Überwachungskamera IOC-221, IP, WLAN, außen | 580950
What happens if I deposit a bounced check?
Gw2 Legendary Amulet
Ncaaf Reference
Cube Combination Wiki Roblox
Shemal Cartoon
Cnnfn.com Markets
Wildflower1967
Binghamton Ny Cars Craigslist
Dump Trucks in Netherlands for sale - used and new - TrucksNL
Raleigh Craigs List
I Wanna Dance with Somebody : séances à Paris et en Île-de-France - L'Officiel des spectacles
Craiglist Tulsa Ok
Yard Goats Score
Qhc Learning
Panolian Batesville Ms Obituaries 2022
yuba-sutter apartments / housing for rent - craigslist
Rust Belt Revival Auctions
A Christmas Horse - Alison Senxation
Geico Car Insurance Review 2024
Vera Bradley Factory Outlet Sunbury Products
Medline Industries, LP hiring Warehouse Operator - Salt Lake City in Salt Lake City, UT | LinkedIn
Hwy 57 Nursery Michie Tn
My Dog Ate A 5Mg Flexeril
Publix Daily Soup Menu
In Branch Chase Atm Near Me
Whas Golf Card
Ixl Lausd Northwest
Everything You Need to Know About NLE Choppa
Foolproof Module 6 Test Answers
The Vélodrome d'Hiver (Vél d'Hiv) Roundup
San Bernardino Pick A Part Inventory
Doordash Promo Code Generator
Panorama Charter Portal
Disassemble Malm Bed Frame
Powerspec G512
Po Box 101584 Nashville Tn
Rise Meadville Reviews
The Significance Of The Haitian Revolution Was That It Weegy
Bunbrat
Latest Posts
Article information

Author: Sen. Ignacio Ratke

Last Updated:

Views: 5764

Rating: 4.6 / 5 (76 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Sen. Ignacio Ratke

Birthday: 1999-05-27

Address: Apt. 171 8116 Bailey Via, Roberthaven, GA 58289

Phone: +2585395768220

Job: Lead Liaison

Hobby: Lockpicking, LARPing, Lego building, Lapidary, Macrame, Book restoration, Bodybuilding

Introduction: My name is Sen. Ignacio Ratke, I am a adventurous, zealous, outstanding, agreeable, precious, excited, gifted person who loves writing and wants to share my knowledge and understanding with you.