LastPass has had to patch a flaw in one of its browser extensions that could have enabled hackers to steal passwords from users after visiting a malicious website.
LastPass is a popular password manager which stores encrypted passwords in private accounts. It offers free and paid-for versions.
Two vulnerabilities were found by seasoned security researcher Tavis Ormandy who works for Googleâs Project Zero.
According to a security advisory posted by Ormandy, the flaw affecting the LastPass Chrome extension works by attacking an intermediary JavaScript code between a browser and LastPassâ cloud service, which stores user passwords.
âThis script will proxy unauthenticated window messages to the extension. This is clearly a mistake,â he said in the advisory. âThis allows complete access to internal privileged LastPass RPC commands. There are hundreds of internal LastPass RPCs, but the obviously bad ones are things copying and filling in passwords (copypass, fillform, etc).â
Ormandy developed proof-of-concept code that launches an application (in this case Windows Calculator), via this JavaScript code. The code could be altered to steal user passwords before they are populated in the browserâs username and password fields.
âThere are a lot of RPCs, allowing complete control of the LastPass extension, including stealing passwords. If you have the âBinary Componentâ installed, this even allows arbitrary code execution,â added Ormandy.
LastPass tweeted that it had already fixed the issue reported by the Google researcher and would publish further details later.
A second bug affects LastPassâs Firefox add-on version 3.3.2 only. According to Ormandy, this only affects LastPassâ Firefox extension, version 3.3.2. As with the Chrome extension, the flaw can be exploited by malicious webpages to extract passwords from the manager. This version of the LastPass add-on is set to be retired by the firm.
Ormandy has also found a similar bug in LastPass version 4.1.35 for Firefox. The researcher is gaining quite a reputation in finding bugs with LastPass. In July last year, he discovered a flaw in LastPass that allowed remote code execution.
This article originally appeared at scmagazineuk.com