/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How third-party scripts on websites exploit a flaw in browsers' built-in password managers to identify and track users

In this second installment of the No Boundaries series, we show how a long-known vulnerability in browsers' built-in password managers is abused by third-party scripts for tracking on more than a thousand sites.

Freedom to Tinker

Context & Ripple Effects

This is not a new bug but a newly weaponized one: a year earlier, researchers showed that [[a:915656|hidden text boxes could trick Chrome, Safari, Opera and extensions like LastPass into leaking private information]], and the Freedom to Tinker piece documents that same password-manager autofill flaw now running at scale in third-party tracking scripts on more than a thousand sites.

It slots into a recurring pattern in the coverage — browser features designed for user convenience quietly doubling as tracking channels, from the favicon cache that survives incognito mode and script blockers to the autofill leak here. Each installment shows the same structure: a trusted browser component exposing state to any script a page loads.

First-order effects

  • Visitors to the 1,000+ affected sites can be identified and tracked across visits even by users who never log in, because the scripts probe the browser's autofill rather than any account system.
  • Browser vendors and password-manager maintainers — the Chrome, Safari, Opera and LastPass teams named in the prior hidden-text-box research — face pressure to change how autofill interacts with invisible form fields.

Second-order effects

  • As cookie blocking and script blockers spread, ad-tech operators have a demonstrated incentive to migrate toward side channels that read browser-internal state, making password managers and caches the new tracking surface.
  • Site operators embedding third-party scripts inherit a privacy liability they did not code themselves, tightening the audit burden on every tag, analytics snippet, and ad loader they include.

Third-order effects

  • If convenience features keep leaking state to page scripts, browsers will have to redraw their trust boundary — treating third-party scripts as untrusted principals with no access to autofill, cache, or profile state — a shift the later finding that 245 extensions override security protections to scrape sites shows is still unfinished.
  • The pattern points toward regulation and platform policy catching up to script-level tracking, since no single vendor patch can close a channel that reopens wherever a trusted feature is readable from page context.

The trend: Browser convenience features are being systematically converted into tracking channels, forcing browser makers to harden the boundary between trusted browser state and untrusted page scripts.

Discussion

  • @profcarroll David Carroll on x
    While you're tinkering with your browser settings be sure to disable the auto-fill feature because devious adtech is stealing your email address and sending it to data brokers without your knowledge or consent. http://www.theverge.com/...
  • @shaneoleary1 Shane O Leary on x
    Heard certain types of digital advertising described as ‘information warfare’ recently. Hard to argue when you see stuff like this going on. “Ad targeters are pulling data from your browser's password manager” http://www.theverge.com/... Our industry needs to be cleaned up in '18…
  • @jcstearns Josh Stearns on x
    Publishers - are digital ads on your sites enabling this kind of privacy invation and tracking of your readers? Do you know? http://www.theverge.com/... http://twitter.com/...
  • @collabjonathan Jonathan Schulenberg on x
    This is simultaneously very clever and alarming. Let's see how long it takes for every browser & password manager to change their behavior and whether the solution is more elegant than requiring user acknowledgement before auto-filling. http://twitter.com/...
  • @julianor Juliano Rizzo on x
    We've seen variants of this password autocomplete stealing bug for years. Do not use “save password” feature of browsers or password managers integrated to the browser. Bugs in domain name parsers, race conditions, injections and attackers have Javascript power to exploit them. h…
  • @tedonprivacy Ted on x
    Abusing security features to track people without knowledge or consent is my favorite kind of Eldritch creepiness. Here, an invisible login form is auto-filled by your browser's credential manager. The page can then retrieve your email address and use it as a tracking ID. http://…
  • @troyhunt Troy Hunt on x
    Good detail on exploit scripts snooping on data stored in browser password managers http://twitter.com/...
  • @mediajustice CMJ on x
    Advertisers are using invisible login forms in the background of webpages and scooping up whatever your browser autofills into the available slots. http://www.theverge.com/...