Hackers can force iOS and macOS browsers to divulge passwords and much more - eviltoast

Hackers can force iOS and macOS browsers to divulge passwords and much more::iLeakage is practical and requires minimal resources. A patch isn’t (yet) available.

  • ilega_dh@feddit.nl
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    The vulnerability seems to be that it can read content filled into a page, and since lastpass will autofill your password (usually, if enabled) it’s easy to read.

    iCloud Keychain requires user intervention by default (using your fingerprint) so it can’t be autofilled in the background.

    Still, many people would be vulnerable because 3rd party password managers are so popular.