• News/
  • https://www.bleepingcomputer.com/news/security/autospill-attack-steals-credentials-from-android-password-managers/

AutoSpill attack steals credentials from Android password managers

BleepingComputer
·
Bill Toulas
·
Published Dec 9, 2023
·
Updated

Security researchers developed a new attack, which they named AutoSpill, to steal account credentials on Android during the autofill operation. In a presentation at the Black Hat Europe security conference, researchers from the International Institute of Information Technology (IIIT) at Hyderabad said that their tests showed that most password managers for Android are vulnerable to AutoSpill, even if there is no JavaScript injection. Android apps often use WebView controls to render web content, such as login pages within the app, instead of redirecting the users to the main browser, which would be a more cumbersome experience on small-screen devices. Password managers on Android use the platform’s WebView framework to automatically type in a user's account credentials when an app loads the login page to services like Apple, Facebook, Microsoft, or Google. The researchers said that it is possible to exploit weaknesses in this process to capture the auto-filled credentials on the invoking app, even without JavaScript injection. If JavaScript injections are enabled, the researchers say that all password managers on Android are vulnerable to the AutoSpill attack. Specifically, the AutoSpill issue stems from Android’s failure to enforce or to clearly define the responsibility for the secure handling of the auto-filled data, which can result in leaking it or being captured by the host app. In an attack scenario, a rogue app serving a login form could capture the user’s credential...

Read full article

Affected Software

8 affected components
Android WebView
1Password 1Password=7.9.4
LastPass LastPass=5.11.0.9519
Enpass Enpass=6.8.2.666
Keeper Keeper=16.4.3.1048
Keepass2Android Keepass2Android=1.09c-r0
Google Smart Lock=13.30.8.26
DashLane DashLane=6.2221.3
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the AutoSpill attack?

The AutoSpill attack is a new security threat that steals account credentials from Android password managers during the autofill operation.

2

Which Android version is affected by the AutoSpill attack?

The AutoSpill attack primarily affects Android devices using the WebView component.

3

What password managers are vulnerable to the AutoSpill attack?

The AutoSpill attack affects several password managers including 1Password, LastPass, Enpass, Keeper, Keepass2Android, Google Smart Lock, and DashLane.

4

What specific versions of affected products are mentioned in the article?

Affected versions mentioned include 1Password 7.9.4, LastPass 5.11.0.9519, Enpass 6.8.2.666, Keeper 16.4.3.1048, Keepass2Android 1.09c-r0, Google Smart Lock 13.30.8.26, and DashLane 6.2221.3.

5

Where was the AutoSpill attack presented?

The AutoSpill attack was presented at the Black Hat Europe security conference.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203