LastPass has advised all users of the password manager to launch sites directly from the LastPass vault and enable two-factor authentication wherever possible, until it addresses a vulnerability discovered in LastPass browser extensions.

The client-side vulnerability, discovered by Google security researcher Tavis Ormandy, allows for an attack that is "unique and highly sophisticated", said LastPass in a blog post, without disclosing further details.

C7yXCacVQAAXz8T

Over the weekend, Google security researcher Tavis Ormandy reported a new client-side vulnerability in the LastPass browser extension. We are now actively addressing the vulnerability. This attack is unique and highly sophisticated. We don’t want to disclose anything specific about the vulnerability or our fix that could reveal anything to less sophisticated but nefarious parties. So you can expect a more detailed post mortem once this work is complete.

To secure sign-in credentials in the meantime, LastPass has recommended that users launch sites directly from the vault and make use of two-factor authentication on sites that offer it, while remaining vigilant to avoid phishing attempts.

The news follows the discovery and successful patching of earlier remote code execution (RCE) vulnerabilities that could be used to steal passwords from extensions for Firefox, Chrome, Opera, and Edge. Safari was not mentioned in the original vulnerability alert, while mobile apps were not affected, but concerned users can follow the advice regardless until LastPass offers further news on the situation.

Top Rated Comments

keysofanxiety Avatar
93 months ago
Great idea, keep all your passwords in one location...
It's a much better idea than using the same password for 50 different websites.
Score: 6 Votes (Like | Disagree)
maflynn Avatar
93 months ago
Last Pass is good enough for Steve Gibson (if you don't know who he is, look him up), and it's good enough for me.
It may be good enough for him, but I'd rather not go with a product that has had numerous issues with vulnerabilities and hacking. Regardless of his security chops, I think storing your data with a company that has such a poor track record of securing your data is not the best move imo.
Score: 3 Votes (Like | Disagree)
burgman Avatar
93 months ago
No, I have the app on my iPad and Mac as well. They don't link with each other I manually have put in my passwords.

And besides if I lose my phone I have a backup on my Mac and in iCloud.

It's like anything if you lose your phone.
So your first post isn't true, you do use cloud services to store passwords.
Score: 1 Votes (Like | Disagree)
iapplelove Avatar
93 months ago
So your first post isn't true, you do use cloud services to store passwords.
First I'm not looking for an argument don't know why people are hating on me. I do not use password services that use the cloud. This is what I was referring to.

I only use iCloud for backups if I am having issues with my Mac which is the main place where I backup my devices.

I don't understand the hostility here?
Score: 1 Votes (Like | Disagree)
zzLZHzz Avatar
93 months ago
I use a simple password app, that doesn't connect to the internet doesn't use the cloud etc.

It's simply just a place to store all my passwords in one place and I just look them up when I need them.

I will never ever use any kind of password service.
what if you lose your phone (i assume the app is on your phone)? won't you lose those password?
Score: 1 Votes (Like | Disagree)
geenosr Avatar
93 months ago
Last Pass is good enough for Steve Gibson (if you don't know who he is, look him up), and it's good enough for me. I've used it for many years and while nothing is ever foolproof, LP is about as good as it gets. They will have this fixed soon and I for one appreciate their transparency.
Score: 1 Votes (Like | Disagree)

Popular Stories

iOS 18 Apple Music Messages and Notes Feature 1

iOS 18 Rumored to Add New Features to These 16 Apps on Your iPhone

Tuesday April 30, 2024 10:44 am PDT by
Apple is expected to announce iOS 18 during its WWDC keynote on June 10, and new features have already been rumored for many apps, including Apple Music, Apple Maps, Calculator, Messages, Notes, Safari, and others. Below, we recap iOS 18 rumors on a per-app basis, based on reports from MacRumors, Bloomberg's Mark Gurman, and others: Apple Maps: At least two new Apple Maps features are...
5

Apple Event This Week Expected to Last 'About 35 Minutes'

Sunday May 5, 2024 3:13 pm PDT by
Apple will be holding its first event of the year this Tuesday, May 7 at 7 a.m. Pacific Time, with a live stream to be available on Apple.com and on YouTube. How long will the event be? In his newsletter today, Bloomberg's Mark Gurman said the video will have a runtime of "around 35 minutes." Apple is expected to announce new iPad Pro and iPad Air models, along with updated Apple Pencil...
top stories 4may2024

Top Stories: Apple Event Preview, iPad Pro With M4 Chip Rumor, New Beats Headphones, and More

Saturday May 4, 2024 6:00 am PDT by
It's been a long time since the last one, but an Apple event is finally right around the corner! While it's anticipated to be a fairly short pre-recorded affair, we're expecting to see the first updates to the iPad lineup in over a year and half, so make sure to tune in to see what Apple has in store. Other news and rumors this week included a couple of product introductions from Apple's...
iOS 17 All New Features Thumb

Apple Says iOS 17.5 Coming 'Soon' With These New Features for iPhones

Monday May 6, 2024 7:33 am PDT by
Apple today announced that iOS 17.5 will be released to the public "soon," following over a month of beta testing. While the software update is relatively minor, it does have a few new features and changes, as outlined in the list below. "The new Pride Radiance watch face and iPhone and iPad wallpapers will be available soon with watchOS 10.5, iOS 17.5, and iPadOS 17.5," said Apple, in its...
2024 Apple Watch Pride Face Feature

Apple Unveils 2024 Pride Edition Braided Solo Loop Band and Watch Face

Monday May 6, 2024 6:11 am PDT by
Apple today announced a new Pride Edition Braided Solo Loop Apple Watch band, watch face, and wallpaper. The band features a fluorescent design inspired by multiple pride flags with a laser-etched lug that reads "PRIDE 2024." Black, Hispanic, and Latin communities, as well as those impacted by HIV/AIDS, are represented on the band by the black and brown colors, while transgender and...