LastPass fixes a bug in its Chrome and Opera extensions which exposed credentials entered on previously visited websites
LastPass has released a fix last week. Vulnerability details are now public. Users advised to update. — Password manager LastPass has released an update last week …
Context & Ripple Effects
This is the second time in three years LastPass has had to ship an emergency fix for its browser extensions: it was already working on one after a newly discovered extension vulnerability surfaced in March 2017. The 2019 incident follows the same shape — a flaw in the extension layer, not the encrypted vault, with vulnerability details now public and users told to update.
It also lands on a company whose security record is doing double duty as its marketing. LastPass weathered a 2015 breach that compromised emails and password reminders while leaving the encrypted vault untouched, and the extension-level flaws show the perimeter problem extends well past server-side attacks.
First-order effects
- Chrome and Opera users running an unpatched LastPass extension had credentials entered on previously visited websites exposed; the immediate action item is updating the extension before attackers weaponize the now-public details.
- LastPass absorbs another disclosure cycle where the fix shipped before the explanation, testing whether its rapid-response cadence holds up against the accumulating record of extension flaws and breaches.
Second-order effects
- Every extension-layer exposure gives enterprise buyers a fresh reason to scrutinize browser-based credential delivery — pushing competitors in the password-manager market to argue architecture (extension surface area vs. vault isolation) rather than features.
- Google's Chrome extension ecosystem takes reputational collateral damage: a high-profile credential tool leaking cross-site data invites harder questions about how much trust third-party extensions should hold over anything typed into the browser.
Third-order effects
- If the pattern holds — extension bugs in 2017 and 2019, then source-code theft in 2022 and stolen vault data by 2023 per LastPass's own disclosure — the industry drifts toward treating a password manager's incident history as the core product attribute, not a footnote.
- Repeated cross-site exposure failures point toward browsers tightening what extensions may touch by default, moving credential autofill closer to platform-controlled territory and shrinking the space independent managers occupy.
The trend: Password managers are shifting from competing on convenience to being judged by their cumulative security track record, as browser vendors and buyers reassess how much of the credential pipeline third-party extensions should handle.