/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

LastPass fixes a bug in its Chrome and Opera extensions which exposed credentials entered on previously visited websites

LastPass has released a fix last week.  Vulnerability details are now public.  Users advised to update.  —  Password manager LastPass has released an update last week …

ZDNet Catalin Cimpanu

Context & Ripple Effects

This is the second time in three years LastPass has had to ship an emergency fix for its browser extensions: it was already working on one after a newly discovered extension vulnerability surfaced in March 2017. The 2019 incident follows the same shape — a flaw in the extension layer, not the encrypted vault, with vulnerability details now public and users told to update.

It also lands on a company whose security record is doing double duty as its marketing. LastPass weathered a 2015 breach that compromised emails and password reminders while leaving the encrypted vault untouched, and the extension-level flaws show the perimeter problem extends well past server-side attacks.

First-order effects

  • Chrome and Opera users running an unpatched LastPass extension had credentials entered on previously visited websites exposed; the immediate action item is updating the extension before attackers weaponize the now-public details.
  • LastPass absorbs another disclosure cycle where the fix shipped before the explanation, testing whether its rapid-response cadence holds up against the accumulating record of extension flaws and breaches.

Second-order effects

  • Every extension-layer exposure gives enterprise buyers a fresh reason to scrutinize browser-based credential delivery — pushing competitors in the password-manager market to argue architecture (extension surface area vs. vault isolation) rather than features.
  • Google's Chrome extension ecosystem takes reputational collateral damage: a high-profile credential tool leaking cross-site data invites harder questions about how much trust third-party extensions should hold over anything typed into the browser.

Third-order effects

  • If the pattern holds — extension bugs in 2017 and 2019, then source-code theft in 2022 and stolen vault data by 2023 per LastPass's own disclosure — the industry drifts toward treating a password manager's incident history as the core product attribute, not a footnote.
  • Repeated cross-site exposure failures point toward browsers tightening what extensions may touch by default, moving credential autofill closer to platform-controlled territory and shrinking the space independent managers occupy.

The trend: Password managers are shifting from competing on convenience to being judged by their cumulative security track record, as browser vendors and buyers reassess how much of the credential pipeline third-party extensions should handle.

Discussion

  • @pinboard @pinboard on x
    YOU HAVE ONE JOB https://twitter.com/...