Close Menu
Hollywood News Reporter
  • Home
  • Film
  • Television
  • Box Office
  • Reality TV
  • Music
  • Horror
  • Books
  • Technology
  • Politics
  • Cover Story
  • Contact
    • About
    • Privacy Policy
    • DMCA / Copyright Disclaimer
    • Amazon Disclaimer
    • Terms and Conditions

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Heavy Song of the Week: Anthrax Deliver Sharp and Direct Thrash with “It’s For the Kids”

The Cute VR Platformer Moss And Its Sequel Are Heading To Consoles

8 Summer Reads About Friends Bonding Over a Pact

Facebook X (Twitter) Instagram
Hollywood News Reporter
  • Home
  • Film
  • Television
  • Box Office
  • Reality TV
  • Music
  • Horror
  • Books
  • Technology
  • Politics
  • Cover Story
  • Contact
    • About
    • Privacy Policy
    • DMCA / Copyright Disclaimer
    • Amazon Disclaimer
    • Terms and Conditions
Hollywood News Reporter
You are at:Home»Technology»Your mobile password manager might be exposing your credentials
Technology

Your mobile password manager might be exposing your credentials

By AdminDecember 6, 2023
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
Your mobile password manager might be exposing your credentials


A number of popular mobile password managers are inadvertently spilling user credentials due to a vulnerability in the autofill functionality of Android apps.

The vulnerability, dubbed “AutoSpill,” can expose users’ saved credentials from mobile password managers by circumventing Android’s secure autofill mechanism, according to university researchers at the IIIT Hyderabad, who discovered the vulnerability and presented their research at Black Hat Europe this week.

The researchers, Ankit Gangwal, Shubham Singh and Abhijeet Srivastava, found that when an Android app loads a login page in WebView, the pre-installed engine from Google that lets developers display web content in-app without launching a web browser, and an autofill request is generated, password managers can get “disoriented” about where they should target the user’s login information and instead expose their credentials to the underlying app’s native fields, they said.

“Let’s say you are trying to log into your favorite music app on your mobile device, and you use the option of ‘login via Google or Facebook.’ The music app will open a Google or Facebook login page inside itself via the WebView,” Gangwal explained to TechCrunch prior to their Black Hat presentation on Wednesday.

“When the password manager is invoked to autofill the credentials, ideally, it should autofill only into the Google or Facebook page that has been loaded. But we found that the autofill operation could accidentally expose the credentials to the base app.”

Gangwall notes that the ramifications of this vulnerability, particularly in a scenario where the base app is malicious, are significant. He added: “Even without phishing, any malicious app that asks you to log in via another site, like Google or Facebook, can automatically access sensitive information.”

The researchers tested the AutoSpill vulnerability using some of the most popular password managers, including 1Password, LastPass, Keeper, and Enpass, on new and up-to-date Android devices. They found that most apps were vulnerable to credential leakage, even with JavaScript injection disabled. When JavaScript injection was enabled, all the password managers were susceptible to their AutoSpill vulnerability.

Gangwal says he alerted Google and the affected password managers to the flaw.

1Password chief technology officer Pedro Canahuati told TechCrunch that the company has identified and is working on a fix for AutoSpill. “While the fix will further strengthen our security posture, 1Password’s autofill function has been designed to require the user to take explicit action,” said Canahuati. “The update will provide additional protection by preventing native fields from being filled with credentials that are only intended for Android’s WebView.”

Keeper CTO Craig Lurey said in remarks shared with TechCrunch that the company was notified about a potential vulnerability, but did not say if it had made any fixes. “We requested a video from the researcher to demonstrate the reported issue. Based upon our analysis, we determined the researcher had first installed a malicious application and subsequently, accepted a prompt by Keeper to force the association of the malicious application to a Keeper password record,” said Lurey.

Keeper said it “safeguards in place to protect users against automatically filling credentials into an untrusted application or a site that was not explicitly authorized by the user,” and recommended that the researcher submit his report to Google “since it is specifically related to the Android platform.”

Google and Enpass did not respond to TechCrunch’s questions. LastPass spokesperson Elizabeth Bassler did not comment by press time.

Gangwal tells TechCrunch that the researchers are now exploring the possibility of an attacker potentially extracting credentials from the app to WebView. The team is also investigating whether the vulnerability can be replicated on iOS.



Original Source Link

Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
Previous ArticleROME’S LAST NOBLE PALACE | Kirkus Reviews
Next Article Concert Ticket Bill Requiring All-In Pricing, Refunds Moves Forward – Billboard

Related Posts

The Cute VR Platformer Moss And Its Sequel Are Heading To Consoles

May 15, 2026

TopResume Packages: Everything You Need to Get Hired

May 15, 2026

Microsoft’s Unreleased Cloud Controller Has Been Spotted In The Wild And It’s Teeny

May 14, 2026

Starz Promo Codes: $5 Off for May 2026

May 14, 2026

The Talos Principle 3 Will Wrap Up The Series

May 13, 2026

H&R Block Coupon: 25% Off DIY + Tax Pro Assist

May 13, 2026
Recent Posts

TopResume Packages: Everything You Need to Get Hired

New Young Adult Books to Read | May 12

‘Scary Movie’ & ‘Masters Of The Universe’ To Freak Each Other Out With $35M+ Openings – Box Office Early Look

Meghan Markle Wishes To Unmask ‘Frosty’ Kate Middleton — Source

China to buy U.S. oil to feed its ‘insatiable appetite,’ Trump tells Fox News

Inde Navarrette’s Performance in ‘Obsession’ Deserves an Oscar

Brat Prince Drops Another Shady Statement With New Single

Categories
  • Books (2,102)
  • Box Office (1,509)
  • Cover Story (42)
  • Featured Stories (33)
  • Film (2,121)
  • Horror (2,108)
  • Music (2,169)
  • Politics (1,260)
  • Reality TV (1,564)
  • Technology (2,115)
  • Television (1,977)
  • Uncategorized (1)
Archives
Useful Links
  • About
  • Contact
  • Privacy Policy
  • DMCA / Copyright Disclaimer
  • Amazon Disclaimer
  • Terms and Conditions
Popular Posts

Did You Know Osgood Perkins Produced ‘Backrooms’?

May 10, 2026

Sadie Robertson Gives Birth to Third Daughter

May 10, 2026

DC Developing Deathstroke and Bane Movie

May 10, 2026

Tekashi 6ix9ine Says Girlfriend Will Have Abortion If Baby Isn’t Boy

May 9, 2026

Porsche Is Discontinuing Its Performance E-Bike Division

May 9, 2026

Our Exclusive Met Gala “Lookbook”

May 9, 2026

‘Devil Wears Prada 2’ Beats Original Movie’s Gross at Box Office

May 9, 2026
Categories
  • Books (2,102)
  • Box Office (1,509)
  • Cover Story (42)
  • Featured Stories (33)
  • Film (2,121)
  • Horror (2,108)
  • Music (2,169)
  • Politics (1,260)
  • Reality TV (1,564)
  • Technology (2,115)
  • Television (1,977)
  • Uncategorized (1)
Recent Posts
  • Heavy Song of the Week: Anthrax Deliver Sharp and Direct Thrash with “It’s For the Kids”
  • The Cute VR Platformer Moss And Its Sequel Are Heading To Consoles
  • 8 Summer Reads About Friends Bonding Over a Pact
  • ‘Obsession’ Makes $2.6M In Previews
  • Doja Cat’s Mini Skirt Is So Tiny, Fans Think It’s Just a Belt
  • Trump mum on U.S. defending Taiwan from China
  • Movie Review: Bloodthirsty | HNN
Our Picks

Heavy Song of the Week: Anthrax Deliver Sharp and Direct Thrash with “It’s For the Kids”

The Cute VR Platformer Moss And Its Sequel Are Heading To Consoles

8 Summer Reads About Friends Bonding Over a Pact

‘Obsession’ Makes $2.6M In Previews

© 2026 Hollywood News Reporter. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

Type above and press Enter to search. Press Esc to cancel.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT