Six major password managers with tens of millions of users are currently vulnerable to unpatched clickjacking flaws that could allow attackers to steal account credentials, 2FA codes, and credit card details. Threat actors could exploit the security issues when victims visit a malicious page or websites vulnerable to cross-site scripting (XSS) or cache poisoning, where attackers overlay invisible HTML elements over the password manager interface. While users believe they are interacting with harmless clickable elements, they trigger autofill actions that leak sensitive information. The flaws were presented during the recent DEF CON 33 hacker conference by independent researcher Marek Tóth. Researchers at cybersecurity company Socket later verified the findings and helped inform impacted vendors and coordinate public disclosure. The researcher tested his attack on certain versions of 1Password, Bitwarden, Enpass, iCloud Passwords, LastPass, and LogMeOnce, and found that all their browser-based variants could leak sensitive info under certain scenarios. The main attack mechanic is to run a script on a malicious or compromised website that uses opacity settings, overlays, or pointer-event tricks to hide the autofill dropdown menu of a browser-based password manager. The attacker then overlays fake intrusive elements (e.g. cookie banners, popups, or CAPTCHA) so that the user’s clicks fall on the hidden password manager controls, resulting in completing the forms with sensitive i...
Major password managers can leak logins in clickjacking attacks
BleepingComputer
·Bill Toulas
·Published Aug 20, 2025
·Updated
Affected Software
6 affected components
Agilebits 1Password
Bitwarden Bitwarden
Enpass Enpass
Apple iCloud Passwords
LogMeOnce LogMeOnce
LastPass LastPass
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses vulnerabilities in major password managers that allow clickjacking attacks to steal sensitive user information.
2
What security implications are discussed in the article?
The article highlights the risk of account credential theft, 2FA code interception, and credit card detail leakage due to unpatched clickjacking flaws.
3
Which major password managers are affected by these vulnerabilities?
Affected password managers include 1Password, Bitwarden, Enpass, iCloud Passwords, LogMeOnce, and LastPass.
4
What type of attack is primarily focused on in this article?
The article focuses on clickjacking attacks, a method that tricks users into clicking on elements hidden on a webpage.
5
What measures should users of affected password managers take?
Users should remain vigilant, avoid suspicious links, and monitor for updates from their password manager providers regarding security patches.