Security researchers developed a new attack, which they named AutoSpill, to steal account credentials on Android during the autofill operation. In a presentation at the Black Hat Europe security conference, researchers from the International Institute of Information Technology (IIIT) at Hyderabad said that their tests showed that most password managers for Android are vulnerable to AutoSpill, even if there is no JavaScript injection. Android apps often use WebView controls to render web content, such as login pages within the app, instead of redirecting the users to the main browser, which would be a more cumbersome experience on small-screen devices. Password managers on Android use the platform’s WebView framework to automatically type in a user's account credentials when an app loads the login page to services like Apple, Facebook, Microsoft, or Google. The researchers said that it is possible to exploit weaknesses in this process to capture the auto-filled credentials on the invoking app, even without JavaScript injection. If JavaScript injections are enabled, the researchers say that all password managers on Android are vulnerable to the AutoSpill attack. Specifically, the AutoSpill issue stems from Android’s failure to enforce or to clearly define the responsibility for the secure handling of the auto-filled data, which can result in leaking it or being captured by the host app. In an attack scenario, a rogue app serving a login form could capture the user’s credential...
AutoSpill attack steals credentials from Android password managers
BleepingComputer
·Bill Toulas
·Published Dec 9, 2023
·Updated
Affected Software
8 affected components
Android WebView
1Password 1Password=7.9.4
LastPass LastPass=5.11.0.9519
Enpass Enpass=6.8.2.666
Keeper Keeper=16.4.3.1048
Keepass2Android Keepass2Android=1.09c-r0
Google Smart Lock=13.30.8.26
DashLane DashLane=6.2221.3
Frequently Asked Questions
1
What is the AutoSpill attack?
The AutoSpill attack is a new security threat that steals account credentials from Android password managers during the autofill operation.
2
Which Android version is affected by the AutoSpill attack?
The AutoSpill attack primarily affects Android devices using the WebView component.
3
What password managers are vulnerable to the AutoSpill attack?
The AutoSpill attack affects several password managers including 1Password, LastPass, Enpass, Keeper, Keepass2Android, Google Smart Lock, and DashLane.
4
What specific versions of affected products are mentioned in the article?
Affected versions mentioned include 1Password 7.9.4, LastPass 5.11.0.9519, Enpass 6.8.2.666, Keeper 16.4.3.1048, Keepass2Android 1.09c-r0, Google Smart Lock 13.30.8.26, and DashLane 6.2221.3.
5
Where was the AutoSpill attack presented?
The AutoSpill attack was presented at the Black Hat Europe security conference.