/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

LastPass working on security update for newly discovered browser extension vulnerability

Florin Bodnarescu / Neowin :

Neowin Florin Bodnarescu

Context & Ripple Effects

This 2017 disclosure lands midway through a decade-long pattern at LastPass: the company disclosed a breach in 2015 that compromised email addresses and password reminders, then spent the following years shipping fixes to its most exposed surface — the browser extension. A nearly identical Chrome and Opera extension bug in 2019 that leaked credentials typed into previously visited sites shows the extension kept generating vulnerabilities long after this update shipped.

What makes this routine-sounding patch matter is where the pattern ends up: by 2022, attackers had moved from poking at the extension to stealing source code outright, and ultimately to exfiltrating customer vault data via a keylogger planted through third-party software. The 2017 fix is an early data point in the erosion of trust that eventually pushed LastPass into company-wide changes and its separation from parent GoTo.

First-order effects

  • Users running the affected browser extension are exposed to whatever the flaw enables until LastPass pushes the update through the extension store.
  • LastPass's support and communications teams absorb another disclosure cycle, on top of the reputational debt still outstanding from the 2015 breach.

Second-order effects

  • Each extension-level fix reinforces that the browser add-on — not the encrypted vault itself — is LastPass's weakest perimeter, steering its engineering investment toward hardening and auditing that code path.
  • Security-conscious customers weighing password managers read every new LastPass advisory against the vendor's cumulative incident record rather than the severity of any single bug, sharpening switching considerations among rivals.

Third-order effects

  • If the pattern holds — and the subsequent source-code theft and 2022 vault-data exfiltration suggest it does — single-vendor cloud password managers face a structural trust problem where the vault's security reputation becomes as much of a product feature as its convenience features.
  • Repeated incidents of this kind push enterprise buyers toward demanding transparency about incident response and architecture, reshaping how password-manager vendors disclose and scope their security updates.

The trend: Password-manager security incidents are migrating from perimeter breaches toward client-side attack surfaces like browser extensions and endpoints, with each disclosure compounding trust costs for cloud vault vendors.