Tuesday, January 21, 2025
HomeSecurity NewsWeb Trackers Exploit Browser Password Managers and Steal Login Information From Browser

Web Trackers Exploit Browser Password Managers and Steal Login Information From Browser

Published on

SIEM as a Service

Follow Us on Google News

A known browser vulnerability exploits the default browser Password manager that abused by third-party scripts and exfiltrate the hidden user identities.

An attacker can be successfully gaining the information by tracking script that inserts an invisible login form in the user visiting website that is automatically filled by browser login manager.

This vulnerability flaw is possibly existing with the browser login manager in all the browsers type and its malicious third-party tracking script exfiltrate the sensitive user information.

Few days before Researcher identified Critical security flaw from well-known browser password manager leads to escalating the privileges of windows and leaked the saved password from the browser.

Tracking scripts are found in more than 1000 website among top 1 Million websites and gathered user addresses that will be hashed later and send it across to third-party servers.

Since Email addresses are unique, hash the email address information and send it across to network because it is an excellent tracking identifier and  The hash of an email address can be used to connect the pieces of an online profile scattered across different browsers, devices, and mobile apps.

Also Read :    Over 500 Million Users PC’s are Secretly Mining CryptoCurrency in Browser without Users Knowledge

How does this Vulnerability Exploit Browser Password Manager

All the web browsers are built-in login managers by default that helps to save user login details to provide an easy user login experience with a set of rules to follow for which login forms will be auto-filled varies by browser.

User information auto filling function doesn’t need any user interaction for all the browsers to auto-filled the username except Chrome.(Crome autofill the password field until the user clicks or touches anywhere on the page).

In this case, a user fills out a login form on the page and asks the browser to save the login. but third party script not presented on the first login page.

Password Manager

When a user visits another page of the same website where the third part script is running and it injects an invisible login form.

Once it injects the malicious script then users information automatically filled in by the browser’s login manager to the invisible login form which contains the username and password fields.

Password Manager

Similar attacks were reported by many researchers especially steal passwords from login managers through cross-site scripting (XSS) attacks.

According to Researchers, Built-in login managers have a positive effect on web security: they curtail password reuse by making it easy to use complex passwords, and they make phishing attacks are harder to mount. Yet, browser vendors should reconsider allowing stealthy access to auto-filled login forms in the light of our findings.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Multiple Azure DevOps Vulnerabilities Let Inject CRLF Queries & Rebind DNS

Researchers uncovered several significant vulnerabilities within Azure DevOps, specifically focusing on potential Server-Side Request...

Hackers Weaponize npm Packages To Steal Solana Private Keys Via Gmail

Socket’s threat research team has identified a series of malicious npm packages specifically designed...

Hackers Weaponize MSI Packages & PNG Files to Deliver Multi-stage Malware

Researchers have reported a series of sophisticated cyber attacks aimed at organizations in Chinese-speaking...

New IoT Botnet Launching Large-Scale DDoS attacks Hijacking IoT Devices

Large-scale DDoS attack commands sent from an IoT botnet's C&C server targeting Japan and...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

LegionLoader Abusing Chrome Extensions To Deliver Infostealer Malware

LegionLoader, a C/C++ downloader malware, first seen in 2019, delivers payloads like malicious Chrome...

North Korean Hackers Stolen $2.2 Billion From Crypto Platforms In 2024

Cryptocurrency hacking incidents in 2024 surged 21.07% YoY to $2.2 billion, with 303 breaches...

Deloitte Denies Breach, Claims Only Single System Affected

Ransomware group Brain Cipher claimed to have breached Deloitte UK and threatened to publish...