LastPass working on security update for newly discovered browser extension vulnerability
Context & Ripple Effects
This 2017 disclosure lands midway through a decade-long pattern at LastPass: the company disclosed a breach in 2015 that compromised email addresses and password reminders, then spent the following years shipping fixes to its most exposed surface — the browser extension. A nearly identical Chrome and Opera extension bug in 2019 that leaked credentials typed into previously visited sites shows the extension kept generating vulnerabilities long after this update shipped.
What makes this routine-sounding patch matter is where the pattern ends up: by 2022, attackers had moved from poking at the extension to stealing source code outright, and ultimately to exfiltrating customer vault data via a keylogger planted through third-party software. The 2017 fix is an early data point in the erosion of trust that eventually pushed LastPass into company-wide changes and its separation from parent GoTo.
First-order effects
- Users running the affected browser extension are exposed to whatever the flaw enables until LastPass pushes the update through the extension store.
- LastPass's support and communications teams absorb another disclosure cycle, on top of the reputational debt still outstanding from the 2015 breach.
Second-order effects
- Each extension-level fix reinforces that the browser add-on — not the encrypted vault itself — is LastPass's weakest perimeter, steering its engineering investment toward hardening and auditing that code path.
- Security-conscious customers weighing password managers read every new LastPass advisory against the vendor's cumulative incident record rather than the severity of any single bug, sharpening switching considerations among rivals.
Third-order effects
- If the pattern holds — and the subsequent source-code theft and 2022 vault-data exfiltration suggest it does — single-vendor cloud password managers face a structural trust problem where the vault's security reputation becomes as much of a product feature as its convenience features.
- Repeated incidents of this kind push enterprise buyers toward demanding transparency about incident response and architecture, reshaping how password-manager vendors disclose and scope their security updates.
The trend: Password-manager security incidents are migrating from perimeter breaches toward client-side attack surfaces like browser extensions and endpoints, with each disclosure compounding trust costs for cloud vault vendors.