Bitwarden is one of several password managers to have released emergency updates for their browser extensions to fix a severe flaw that hackers can exploit to steal passwords, two-factor authentication codes and payment-card details.
Dashlane, Keeper, LastPass, LogMeOnce, NordPass, Proton Pass and RoboForm have also all released updates to fix the flaw, but Apple has yet to release a new version of iCloud Passwords.
The flaw was discovered by independent security researcher Marek Tóth and presented at the DEF CON 33 security conference in Las Vegas in August.
He described it as a clickjacking flaw, in which hackers can hide invisible buttons and forms on a website and trick password extensions into automatically filling in personal details.
The flaw isn’t with the password managers themselves, but how they interact with…
