Windows 10 Password Manager bug allows hackers to steal passwords

Costea Lestoc By: Costea Lestoc
2 minute read

Home » News » Windows 10 Password Manager bug allows hackers to steal passwords

Tavis Ormandy, a security researcher at Google, had recently discovered a vulnerability lurking in Windows 10’s Password Manager. This bug allows cyber attackers to steal passwords.

This flaw comes with the third-party Keeper password manager application that comes pre-installed on all Windows 10 devices. It seems that this flaw is quite similar to the one that the same security researcher discovered back in 2016.

Details regarding the cyber attack

Tavis Ormandy stated that he remembers filing a bug about the way that privileged UI was injected into pages. He claimed that this time it happens again the same thing that happened back in 2016 with the current version of Password Manager.

Tavis demonstrated the attack, and he shared all the necessary details in Project Zero. This bug seems to be subjected to a 90-day disclosure deadline, and this means that after these 90 days pass, Tavis will be free to share the complete details of this flaw and the manner in which it can be exploited publically.

According to him, he created a new Windows 10 VM with a pristine image from MSDN, and he noticed that a third-party password manager comes installed by default. After that, he found the critical vulnerability.

The issue is already flagged, and a fix was rolled out

Windows 10 Password Manager bugs

Keeper already flagged the problem a few days ago, and a new update was rolled out to fix it. The company discussed the issue in a blog post.

Keeper’s post states that all customers who are running the browser extension on Chrome, Edge, and Firefox already received Version 11.4.4 through their web browser extension update process. Users who are running the Safari extension can manually update to version 11.4.4 by visiting the company’s download page. Keeper also said that the mobile and desktop apps were not affected by this problem and they do not require updating.

To prevent any cyber attacks, we recommend that you keep all your apps updated. You can download the extension for Microsoft Edge from the Microsoft store.

RELATED STORIES TO CHECK OUT:

Discussions

Next up

How can I recover PowerPoint passwords within minutes?

Daniel Segun By: Daniel Segun
5 minute read

Microsoft PowerPoint presentations usually contain important, sometimes classified, documents. Hence, most people tend to password-protect such documents against unauthorized access. However, what happens if you […]

Continue Reading

5 automated receptionist software for increased productivity

Madhuparna Sukul avatar. By: Madhuparna Sukul
Less than a 1 minute read

The reception desk is the face and voice of any organization. An automated receptionist software simplifies the entire process of visitor management. Whether it’s the customer, […]

Continue Reading

Top 4 software to recover lost email account passwords

Tashreef Shareef avatar. By: Tashreef Shareef
Less than a 1 minute read

Whether you use web-based email services or desktop email clients to manage your account, emails are used for business and personal communication by almost everyone. […]

Continue Reading