IIIT-Hyderabad researchers show how hackers can steal account details via Android password managers, Google responds

Researchers from IIIT at Hyderabad presented at Black Hat Europe security conference, revealing that most Android password managers are vulnerable to the AutoSpill hacking attack. This attack allows malicious apps to steal user data during autofill, even without JavaScript injection. The vulnerability stems from Android's lack of clear guidelines for handling autofilled data, leaving room for interception. Several popular password managers, including 1Password, LastPass, and Keeper, were found to be vulnerable. However, Google Smart Lock and DashLane, which utilize a different autofill approach, did not leak data unless JavaScript injection was used.

from Gadgets News – Latest Technology News, Mobile News & Updates https://ift.tt/i34CXbu

No comments

Powered by Blogger.