Even password manager LastPass can be fooled. A Google security researcher has found a way to remotely hijack the software.
It works by first luring the user to a malicious site. The site will then exploit a flaw in a LastPass add-on for the Firefox browser, giving it control over the password management software.
LastPass wrote about the vulnerability on Wednesday and said that a fix is already out for Firefox users.
Google security research Tavis Ormandy first discovered the issue. When examining the password manager, he tweeted on Tuesday, “Are people really using this lastpass thing? I took a quick look and can see a bunch of obvious critical problems. I’ll send a report asap.”
Read more here:: IT news – Security