A vulnerability has been fixed in LastPass that could have led to data leaks.

Last week, developers of the popular password manager LastPass released an update that fixes a vulnerability which could have led to the leaking of user data. The issue was announced after it was resolved, and LastPass users were advised to update their password manager to the latest version.

This vulnerability allowed attackers to steal data entered by users on the last visited website. The problem was discovered last month by Tavis Ormandy, a member of Google's Project Zero, which conducts research in the field of information security.  

A vulnerability has been fixed in LastPass that could have led to data leaks.

Currently, LastPass is the most popular password manager. The developers resolved the previously mentioned vulnerability in version 4.33.0, which was made publicly available on September 12. If users do not utilize LastPass's automatic update feature, they are advised to manually download the latest software version as soon as possible, since after the vulnerability was fixed, researchers published details that could be used by attackers to steal passwords from devices where the application has not yet been updated.

Exploitation of the vulnerability is related to executing malicious JavaScript code on the target device without any user interaction. Attackers may lure users to malicious websites with the aim of stealing credentials stored in the password manager. Tavis Ormandy believes that exploiting the vulnerability is quite simple, as attackers can disguise the malicious link, tricking the user into clicking it to steal credentials entered on the previous site.

Representatives of LastPass have not commented on the situation. Currently, there are no known cases of this vulnerability being exploited by attackers.



Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster