LastPass fixes vulnerability in Authenticator Android app that let you bypass PIN/fingerprint lock to access 2FA codes; flaw was reported to LastPass in June
UPDATE: The issue has been fixed. Please see below. — I've found a really easy way to bypass the fingerprint/PIN authentication that protects all of your 2FA codes.
Context & Ripple Effects
LastPass built its own authenticator app after launching one for Android, iOS, and Windows Phone in 2016, positioning it as a TOTP companion to the vault. This story closes a loop on that product: a researcher found a way past the PIN/fingerprint screen protecting stored 2FA codes, reported it in June, and LastPass shipped the fix at the end of December.
The multi-month gap between report and patch matters because it is not an isolated slip — LastPass had already [[a:945913|fixed a Chrome and Opera extension bug that exposed credentials entered on previously visited sites]], making client-side lock and input handling a recurring weak point across its apps.
First-order effects
- Android users who relied on the app's PIN or fingerprint lock had their TOTP codes readable by anyone with brief physical access to an unlocked phone until they installed the fix.
Second-order effects
- For a company whose trust position was already fragile — the 2015 breach disclosure preceded this, and the later source-code theft and vault lockouts followed — each client-side bug gives users a concrete reason to move codes off LastPass Authenticator onto separate apps or hardware tokens.
Third-order effects
- The recurring pattern of local-lock bypasses in password-manager companions points toward software-only device locks being treated as convenience, not security, pushing the industry toward hardware-backed or OS-level protection for second factors.
The trend: Password managers bundling their own authenticator apps keep accumulating local-bypass flaws, steadily shifting user trust away from all-in-one credential apps toward separated, hardware-anchored authentication.