Is My Version of LastPass Impacted By Security Flaws?

LastPass has been busy fixing significant security flaws discovered that allowed malicious websites to steal password and log in information for users.

LastPass Security Flaws

When using a password manager, the last thing you need is for your passwords to be leaked through a critical bug in the program. Bugs have been found in LastPass, in both Chrome and Firefox add-ons. The password manager LastPass needs to patch major security flaws that allow malicious websites to steal passphrases from millions of victims.

Tavis Ormandy, a professional hacker working for Google’s crack Project Zero security team, found the programming issues with LastPass. He discovered that it’s possible to exploit the Chrome extension content script. Web pages with malicious software can easily attack through LastPass, extracting usernames and passwords. Clearly, this is a huge problem, as this allows hackers to gain access to almost anything people are using the password manager for.

The passwords and usernames stored by LastPass are stored in the cloud. When you use LastPass and visit any sites you have saved passwords for, LastPass will automatically fill out login information for you. This makes it easy to surf the net without having to worry about remembering passwords. The problem is, now that the system can be easily hacked, your passwords are accessible to anyone trying to steal them.

Ormandy further showed that it’s possible to use the script and perform commands on the computer of the victim, making it possible for the website to put malware on the computer. This malware installation only works for computer users who have installed the binary component of LastPass.

It’s easy to hack into according to Ormandy and only requires to short lines of JavaScript to break into the system of a victim through LastPass security flaws.

Joe Siegrist, co-founder and VP of LastPass stated, “We greatly appreciate the work of the security community to challenge our product and uncover areas that need improvement.”

Thanks to the quick work of Ormandy, LastPass was able to fix the problems with the software and encourages all users to always keep up with updates so that their system is always running with the latest software version.

Ormandy then discovered another problem for LastPass software engineers. He found that there is a further vulnerability in the Firefox extension. It’s a similar vulnerability, as dangerous web pages can get passwords and steal critical information. While the bug has been addressed, the security patch has to be approved by Firefox. It is in the Mozilla review process and will be out to users shortly.

LastPass is making it clear that bugs have been patched to avoid malicious websites from stealing passwords. LastPass is encouraging all users to make sure they are running the most recent version of the software and to update all extensions if the software doesn’t do it automatically.

LastPass states that the most current versions of their software are 4.1.36 with Firefox, 4.1.43.82 with Chrome, 4.1.30 with Edge, and 4.1.28 with Opera.

Share this post

Invotec Solutions IconInvotec Solutions

Unit 9/148 Chesterville Road, Cheltenham

5.0 7 reviews

  • Avatar Matt Wilde ★★★★★ 3 months ago
    Working with an education solutions expert such as Invotec has meant that we have had a collaborative partner every step of the way in the development of, not only our ICT network infrastructure, but also in determining how best to engage … More students, deliver content, and drive learning outcomes.
  • Avatar Daniel McNairn ★★★★★ 11 months ago
    Invotec Solutions is a great company. Working in the education field they have been great support when we have had technical issues that have needed high level solutions. I know they have worked throughout the Catholic Education system … More and have always delivered a high level of service and support. Very easy to deal with and friendly support.
  • Avatar Marcia Reynolds ★★★★★ 10 months ago
    Invotec were fantastic! Being a small business owner and IT illiterate, Invotec helped me to get up and operating without an issue.
    I now feel secure knowing that they are there to back me up.
  • Avatar Aaron Hawke ★★★★★ a year ago
    I had the pleasure of working with the Invotec Solutions Team for our Cyber Security requirements. They really know their stuff and my expectations were well exceeded. Thanks Guys, You made it easy!
  • Avatar Korin Roehm ★★★★★ 2 years ago
    Invotec has been a great partner to our company. They're very quick and responsive. If you talk to anyone there you know that they're very knowledgeable in the work that they do.
  • Avatar Jan Chapman ★★★★★ 4 years ago
    Invotec really know their stuff, a great company that want to provide the best service possible. I highly recommend them.

Get a Quote