Fake malware apps cause some password managers to surrender logins

(Image credit: Shutterstock)

A large number of top password managers may be vulnerable to cyberattack by fake applications, new reports have warned.

Researchers at the University of York found that two out of five password managers gave out customer details when presented with a fake malicious Google app.

While the researchers did not delve into specific details, most of the tested password manager applications had weak criteria of identifying rogue apps, which resulted in this vulnerability being so damaging.

Inadequate security

The researchers added that if hackers are somehow successful in getting victims to install such fake applications, there is a chance they could get easily access to the passwords.

Since many password manager apps do not impose a login limit using a pin or other login, these apps can often be hacked into with the help of a brute force password attack in just over a couple of hours.

Senior author of the study, Dr Siamak Shahandashti from the Department of Computer Science at the University of York, noted that “Because they are gatekeepers to a lot of sensitive information, rigorous security analysis of password managers is crucial. Our study shows that a phishing attack from a malicious app is highly feasible – if a victim is tricked into installing a malicious app it will be able to present itself as a legitimate option on the autofill prompt and have a high chance of success.”

He also suggested that these commercial password managing apps should deploy additional screening measures before sharing password details with other apps and also use better security mechanism to limit login attempts.

While password managers are entrusted to securely remember unique and complex passwords, it becomes imperative for the companies behind these apps to ensure that their applications are safe and are not prone to hack easily. 

Via: IT Pro

Jitendra Soni

Jitendra has been working in the Internet Industry for the last 7 years now and has written about a wide range of topics including gadgets, smartphones, reviews, games, software, apps, deep tech, AI, and consumer electronics.  

Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound