By using this site, you agree privacy policies
Accept
Geek RoomGeek RoomGeek Room
  • Home
  • Tech
    TechShow More
    Split Technology Park welcomes first tenants: 26 MPSs and 6 startups
    October 31, 2024
    INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans
    October 31, 2024
    Diaspora 4 Innovation: Kick-off event launches a new era for Albanian higher education
    October 31, 2024
    AI for good: Generative AI – Tirana chapter empowers Albanian Youth in tech innovation
    October 29, 2024
    Business Angel Summit 2024: Pioneering Investment and Startup Growth in Sarajevo
    October 29, 2024
  • Mobile
    MobileShow More
    Xiaomi 15 and 15 Pro set to launch on October 29: Official renders released
    October 24, 2024
    Dangerous virus infects millions of mobile phones through popular apps
    October 3, 2024
    The new iPhone 16 arrives in Croatia with a steep price tag
    September 26, 2024
    Beware of these phone numbers: Block them immediately to avoid scams
    September 11, 2024
    Beyond the brand: What really matters when buying a mobile phone
    September 5, 2024
  • Apps
    AppsShow More
    Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content
    October 31, 2024
    Intel prevails in long-running legal battle against €1 billion EU fine
    October 31, 2024
    New definition of open source artificial intelligence released by OSI
    October 29, 2024
    CaSys introduces “Pay by Link” payment service for SMEs in Macedonia
    October 24, 2024
    Kickstarter surpasses $8 billion in donations across all projects
    October 17, 2024
  • Science
    ScienceShow More
    Sofia Tech Park: A thriving innovation hub for Southeast Europe
    October 29, 2024
    Breakthrough in prostate cancer treatment: Croatian scientists develop Vini, a tool to predict effective drug combinations
    October 24, 2024
    Digital Realty partners with Ecolab to pilot AI-powered water conservation solution
    October 24, 2024
    Sofia Tech Park to host the Southeast European Innovators Challenge Conference
    October 11, 2024
    ACG accelerates European growth with major expansion in Croatia
    October 9, 2024
  • Gaming
    GamingShow More
    “Windblown” – The new game from the creators of Dead Cells
    October 24, 2024
    Kraken Empire’s Journey and the creative brilliance of Toy Tactics
    October 21, 2024
    Serbian game studio Tricoman set to make a mark with their new RPG ‘Godforged’ on Steam
    October 16, 2024
    Release the demon with Kill Knight: A phenomenal combat experience with untapped potential
    October 14, 2024
    Nordeus launches new football game “Top Goal: Football Champion” in Serbia
    October 9, 2024
  • Cars
    CarsShow More
    Serbia signs strategic agreement with Hyundai Engineering for 1 GW of Solar Power
    October 16, 2024
    Stara Zagora: Poised to lead Bulgaria’s automotive revolution
    October 15, 2024
    Dacia unveils new Bigster: The flagship model for the C-SUV segment
    October 9, 2024
    Kineton Albania: Pioneering innovation in the automotive industry
    October 8, 2024
    Albania’s vehicle numbers surge in 2024: 73% of registered cars are over 15 years old
    August 20, 2024
  • Entertainment
    EntertainmentShow More
    Where are Generation Z’s famous tech entrepreneurs?
    October 29, 2024
    AllWeb offers special discounts for startups: A unique opportunity for networking and growth
    October 23, 2024
    Montenegro census reveals no ethnic majority, Montenegrins and Serbs nearly equal
    October 16, 2024
    “Primordial Passion” is the first luxury Albanian watch valued at €1.4 million by Argjendari Pirro
    October 15, 2024
    Albania takes the stage at BIG event Paris: Culture and innovation as economic drivers
    October 12, 2024
Search
Reading: Researchers from IIIT Hyderabad found a way to hack a mobile password manager
Notification Show More
Aa
Geek RoomGeek Room
Aa
  • Tech
  • Mobile
  • Apps
  • Science
  • Gaming
  • Cars
  • Entertainment
Search
  • Home
  • Tech
  • Mobile
  • Apps
  • Science
  • Gaming
  • Cars
  • Entertainment
Geek Room > Blog > Tech > Researchers from IIIT Hyderabad found a way to hack a mobile password manager
Tech

Researchers from IIIT Hyderabad found a way to hack a mobile password manager

Last updated: 2023/12/07 at 5:53 PM
Share
4 Min Read

A critical vulnerability, named “AutoSpill,” has been discovered in the autofill functionality of Android apps, leading several popular mobile password managers to inadvertently expose user credentials. Researchers from the IIIT Hyderabad presented their findings at Black Hat Europe, shedding light on the potential risks associated with this security flaw.

Black Hat is an internationally recognized cybersecurity event series providing the most technical and relevant information security research

The AutoSpill vulnerability enables the exposure of saved credentials from mobile password managers by bypassing Android’s secure autofill mechanism. This flaw, as identified by Ankit Gangwal, Shubham Singh, and Abhijeet Srivastava, becomes apparent when an Android app loads a login page in WebView, causing password managers to misdirect autofill to the app’s native fields. WebView, a preinstalled engine from Google, allows developers to display web content within an app without launching a separate web browser.

To illustrate, when logging into a mobile app using the “login via Google or Facebook” option, WebView opens a Google or Facebook login page within the app. The password manager, designed to autofill credentials, may inadvertently expose them to the app’s native fields instead of limiting autofill to the loaded Google or Facebook page. This disorientation in autofill targeting creates a vulnerability that could potentially be exploited by a malicious app.

LastPass is a password manager and vault app that helps you secure your passwords with encryption, dark web monitoring, and multifactor authentication

The researchers emphasize that the consequences of the AutoSpill vulnerability are particularly significant in scenarios involving a malicious base app. Even without resorting to phishing tactics, a rogue app could coerce users into logging in via Google or Facebook, automatically gaining access to sensitive information.

The researchers conducted tests on popular password managers, including 1Password, LastPass, Keeper, and Enpass, using new and up-to-date Android devices. They found that most apps were vulnerable to credential leakage, even with JavaScript injection disabled. Enabling JavaScript injection increased susceptibility, affecting all tested password managers.

Upon discovering the flaw, Ankit Gangwal promptly alerted Google and the affected password manager providers. 1Password’s Chief Technology Officer, Pedro Canahuati, mentioned that they are actively working on a fix to strengthen their security posture. Keeper’s Chief Technology Officer, Craig Lurey, acknowledged notification of a potential vulnerability but did not disclose whether fixes were implemented. LastPass had pre-existing mitigation in place, which was further enhanced after analyzing the researchers’ findings.

Keeper Security, Inc. is a provider of zero-knowledge security and encryption software covering password management, secrets management and connection management among other offerings

The researchers are now exploring the potential for attackers to extract credentials from the app to WebView. Additionally, they are investigating whether the AutoSpill vulnerability can be replicated on iOS.

The AutoSpill vulnerability serves as a stark reminder of the intricate security challenges facing mobile password managers. As providers work diligently to address and patch these vulnerabilities, users are advised to stay vigilant and consider additional security measures to safeguard their sensitive information. The collaborative efforts between researchers and providers play a crucial role in maintaining the integrity of password management systems and ensuring user data remains protected.

You Might Also Like

Split Technology Park welcomes first tenants: 26 MPSs and 6 startups

INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans

Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content

Intel prevails in long-running legal battle against €1 billion EU fine

Diaspora 4 Innovation: Kick-off event launches a new era for Albanian higher education

Share This Article
Facebook Whatsapp Whatsapp Copy Link
Previous Article iOS 17.2: Apple reveals exciting new features like the Journal App and more
Next Article How to train your brain to achieve success in your 2024 New Year’s resolutions

Social networks

Instagram Follow

Latest news

Split Technology Park welcomes first tenants: 26 MPSs and 6 startups
Tech October 31, 2024
INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans
Tech October 31, 2024
Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content
Apps October 31, 2024
Intel prevails in long-running legal battle against €1 billion EU fine
Apps October 31, 2024

Related articles

Tech

Split Technology Park welcomes first tenants: 26 MPSs and 6 startups

October 31, 2024
Tech

INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans

October 31, 2024
Apps

Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content

October 31, 2024
Apps

Intel prevails in long-running legal battle against €1 billion EU fine

October 31, 2024

About us

Geek Room is dedicated to technology and its enthusiasts through real-time information and videos about the latest innovations. Connect with our staff via email at: [email protected]
For cooperation opportunities, write to us at: [email protected]

Find us:

© 2023 Geekroom All Rights Reserved. Developed by MIMS
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?