• News/
  • https://www.bleepingcomputer.com/news/security/major-password-managers-can-leak-logins-in-clickjacking-attacks/

Major password managers can leak logins in clickjacking attacks

BleepingComputer
·
Bill Toulas
·
Published Aug 20, 2025
·
Updated

Six major password managers with tens of millions of users are currently vulnerable to unpatched clickjacking flaws that could allow attackers to steal account credentials, 2FA codes, and credit card details. Threat actors could exploit the security issues when victims visit a malicious page or websites vulnerable to cross-site scripting (XSS) or cache poisoning, where attackers overlay invisible HTML elements over the password manager interface. While users believe they are interacting with harmless clickable elements, they trigger autofill actions that leak sensitive information. The flaws were presented during the recent DEF CON 33 hacker conference by independent researcher Marek Tóth. Researchers at cybersecurity company Socket later verified the findings and helped inform impacted vendors and coordinate public disclosure. The researcher tested his attack on certain versions of 1Password, Bitwarden, Enpass, iCloud Passwords, LastPass, and LogMeOnce, and found that all their browser-based variants could leak sensitive info under certain scenarios. The main attack mechanic is to run a script on a malicious or compromised website that uses opacity settings, overlays, or pointer-event tricks to hide the autofill dropdown menu of a browser-based password manager. The attacker then overlays fake intrusive elements (e.g. cookie banners, popups, or CAPTCHA) so that the user’s clicks fall on the hidden password manager controls, resulting in completing the forms with sensitive i...

Read full article

Affected Software

6 affected components
Agilebits 1Password
Bitwarden Bitwarden
Enpass Enpass
Apple iCloud Passwords
LogMeOnce LogMeOnce
LastPass LastPass
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses vulnerabilities in major password managers that allow clickjacking attacks to steal sensitive user information.

2

What security implications are discussed in the article?

The article highlights the risk of account credential theft, 2FA code interception, and credit card detail leakage due to unpatched clickjacking flaws.

3

Which major password managers are affected by these vulnerabilities?

Affected password managers include 1Password, Bitwarden, Enpass, iCloud Passwords, LogMeOnce, and LastPass.

4

What type of attack is primarily focused on in this article?

The article focuses on clickjacking attacks, a method that tricks users into clicking on elements hidden on a webpage.

5

What measures should users of affected password managers take?

Users should remain vigilant, avoid suspicious links, and monitor for updates from their password manager providers regarding security patches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203