• News/
  • https://www.zdnet.com/article/six-of-the-most-popular-android-password-managers-are-leaking-data/

Six of the most popular Android password managers are leaking data

ZDNet
·
Jack Wallen
·
Published Dec 11, 2023
·
Updated

Several mobile password managers are leaking user credentials due to a vulnerability discovered in the autofill functionality of Android apps. The credential-stealing flaw, dubbed AutoSpill, was reported by a team of researchers from the International Institute of Information Technology Hyderabad at last week's Black Hat Europe 2023 conference. Also: The best password managers to save you from login hassle The vulnerability comes into play when Android calls a login page via WebView. (WebView is an Android component that makes it possible to view web content without opening a web browser.) When that happens, WebView allows Android apps to display the content of the web page in question. That's all fine and good -- unless a password manager is added to the mix: The credentials shared with WebView can also be shared with the app that originally called for the username and password. If the originating app is trusted, everything should be OK If that app isn't trusted, things could go very wrong. The affected password managers are 1Password, LastPass, Enpass, Keeper, and Keepass2Android. Also, if the credentials were shared via a JavaScript injection method, both DashLane and Google Smart Lock are also affected by the vulnerability. It is important to note, however, that (according to Rob Blackwelder at Enpass) this was patched with Enpass version 6.8.3, which was released on September 29, 2022. So if you're using any version of that password manager equal to or newer than that, y...

Read full article

Affected Software

7 affected components
Unknown
Unknown
Unknown
Unknown
Unknown
Unknown
Unknown
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a vulnerability in the autofill functionality of Android apps that affects several popular password managers.

2

What security implications are discussed?

The article highlights how the credential-stealing flaw, named AutoSpill, could lead to unauthorized access to user credentials.

3

Which password managers are affected by this vulnerability?

The affected password managers include 1Password, LastPass, Enpass, Keeper, Keepass2Android, DashLane, and Google Smart Lock.

4

Who reported the vulnerability affecting these password managers?

The vulnerability was reported by a team of researchers from a cyber security organization.

5

What should users of the affected password managers do to protect their credentials?

Users are advised to monitor their accounts closely and consider alternative security measures until the flaw is patched.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203