Friday, September 4, 2026

Windows Default Password Manager Keeper Leaked Saved Passwords From Browser

A keeper password manager preinstalled with fresh Windows 10 OS which contains a serious security flaw that discovered by Google most respective security researcher Tavis Ormandy who is working a part of Google Zero Project.

This Critical security flaw from password manager leads to escalating the privileges of windows and leaked the saved password from the browser.

Tavis said, “I assume this is some bundling deal with Microsoft. I’ve heard of Keeper, I remember filing a bug a while ago about how they were injecting privileged UI into pages” Amazingly, they’re doing the exact same thing again with this version.

Also Read:  Hackers Steal More than 19 Million Records of California State Voter Database

A Clickjacking technique is playing a major role in this case and execute privileged code within the browser extension while keeper user accessing the malicious website.

Tavis  Demonstrate this flaw where this clearly explained that how to steal the password for any website from a Keeper user.

Also he said, I recently created a fresh Windows 10 VM with a pristine image from MSDN, and found that a password manager called “Keeper” is now installed by default. I’m not the only person who has noticed but already a windows user have been reported in Reddit.

It was reported to the keeper and they said, To resolve this issue, we removed the “Add to Existing” flow and have taken additional steps to prevent this potential vulnerability in the future. Even though no customers were adversely affected by this potential vulnerability, we take all reported security issues, vulnerabilities, and bug report seriously.

According to Travis, This bug is subject to a 90-day disclosure deadline. After 90 days elapse or a patch has been made broadly available, the bug report will become visible to the public.

All customers running Keeper’s browser extension on Edge, Chrome, and Firefox have already received Version 11.4.4 through their respective web browser extension update process. Customers using the Safari extension can manually update to version 11.4.4 by visiting Keeper’s download page. Keeper said.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Fewer attacks, more force: Link11’s European Cyber Report finds new DDoS records for the first half of 2026

Frankfurt am Main, Germany, September 3rd, 2026, CyberNewswire Super-botnets and...

Fake Acquisition Scam Uses Forged NDAs to Demand €626,000 Corporate Payment.

Threat actors impersonated Gen executives and major consulting firms...

Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems

A malicious ScreenConnect campaign in which rogue remote-access clients...

QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes

QR code phishing, widely known as “quishing,” has reached...

Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks

Microsoft will start automatically enabling Memory Integrity protection on...

New $7 SweepLED Gadget Detects Hidden Cameras With 94% Accuracy in 5 Seconds

Researchers have developed SweepLED, a smartphone-based hidden-camera detection system...

Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell

A public proof-of-concept (PoC) repository has revealed a local...

HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning

QR-code phishing, commonly known as quishing, is evolving beyond...

Related Articles

Recent News