Bitwarden Patches Critical Password Vault Flaw
Source: bit.ly
- Bitwarden fixed a critical zero-click vulnerability letting attackers steal vault data via malicious iframes.
- Exploit tricked browsers into auto-filling credentials outside the app's secure context.
- Update to 2024.8.1 immediately blocks the attack on desktop and browser extensions.
Bitwarden disclosed and patched a serious security flaw in its password manager that allowed hackers to steal stored credentials without user interaction. The bug exploited browser autofill features, bypassing Bitwarden's protections. It affects millions of users, highlighting risks in how password managers integrate with web browsers.