Collected research
DOM-based Extension Clickjacking: Your Password Manager Data at Risk
A single click on an attacker's page can make a password manager autofill its stored data into a hidden form: script hides the extension's injected autofill interface by setting opacity, or covers it with a transparent overlay. A click on a fake cookie banner then leaks card details, credentials and one-time codes, and can hijack a passkey assertion.
Record
- Researcher
- Marek Tóth and @MarekToth
- Published by
- marektoth.com
- Date
- Topic
- Browser
In the archive
Related sources
- DEF CON 33 slides Whitepaper
- Demonstration sites and scripts
- 1password demonstration
- 1password-visible demonstration
- lastpass demonstration
- lastpass-visible demonstration
- bitwarden2 demonstration
- icloudpassword demonstration
- icloudpassword-visible demonstration
- logmeonce demonstration
- logmeonce-visible demonstration
- keepassxc1992 demonstration
Tags
This page is the archive's own catalogue record. The research is the work of Marek Tóth and @MarekToth, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .