Skip to main content

You should update the LastPass password manager browser extension immediately

The developers behind popular password manager LastPass have patched a loophole that exposed your last used password. Originally discovered in August by Tavis Ormandy, a researcher from Google’s Project Zero, the security flaw allowed malicious websites to trick the browser extension into giving away credentials you entered on a previous site.

LastPass says it rolled out an update for the browser add-on on September 13th, two weeks after the vulnerability was first reported by Ormandy.

Recommended Videos

In order to exploit the bug — which possibly only existed on Google Chrome and Opera — attackers simply had to create a fraudulent link masquerading as a URL from websites someone would trust, such as Google Translate. Once the person clicked the link, the hack required no user interaction and immediately executed an automated script which extracted your last used password.

Please enable Javascript to view this content

“We quickly worked to develop a fix and verified the solution was comprehensive with Tavis. We have now resolved this bug; no user action is required and your LastPass browser extension will update automatically,” the company added in a blog post.

While the circumstances for the bug’s misuse are limited, these activities are common on the internet and even if they affected a fraction of LastPass’ user base, it would have cost thousands of users their sensitive data.

The fix should be applied to your browser automatically. However, it’s best to double-check by manually updating the LastPass extension.

How to manually update the LastPass password manager

To manually updated LastPass, click the three-dots at the top right corner of Google Chrome and go to More Tools > Extensions. Scroll down until you find LastPass. Click the Details button on LastPass’ card and then hit the Update button at the top.

On Opera, you can’t force updates and your only option is to reinstall the extension.

Even though you’d expect password managers to be built on the most secured frameworks, security vulnerabilities such as this one can happen. A similar security vulnerability on LastPass’ browser extension previously enabled malicious attackers to steal users’ passwords. Therefore as an added security measure, we recommend switching on two-factor authentication for your accounts.

Shubham Agarwal
Former Digital Trends Contributor
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
PayPal vs. Venmo vs. Cash App vs. Apple Cash: which app should you use?
PayPal, Venmo, Cash App, and Apple Wallet apps on an iPhone.

We’re getting closer every day to an entirely cashless society. While some folks may still carry around a few bucks for emergencies, electronic payments are accepted nearly everywhere, and as mobile wallets expand, even traditional credit and debit cards are starting to fall by the wayside.

That means many of us are past the days of tossing a few bills onto the table to pay our share of a restaurant tab or slipping our pal a couple of bucks to help them out. Now, even those things are more easily doable from our smartphones than our physical wallets.

Read more
How to change margins in Google Docs
Laptop Working from Home

When you create a document in Google Docs, you may need to adjust the space between the edge of the page and the content --- the margins. For instance, many professors have requirements for the margin sizes you must use for college papers.

You can easily change the left, right, top, and bottom margins in Google Docs and have a few different ways to do it.

Read more
What is Microsoft Teams? How to use the collaboration app
A close-up of someone using Microsoft Teams on a laptop for a videoconference.

Online team collaboration is the new norm as companies spread their workforce across the globe. Gone are the days of primarily relying on group emails, as teams can now work together in real time using an instant chat-style interface, no matter where they are.

Using Microsoft Teams affords video conferencing, real-time discussions, document sharing and editing, and more for companies and corporations. It's one of many collaboration tools designed to bring company workers together in an online space. It’s not designed for communicating with family and friends, but for colleagues and clients.

Read more