Fake malware apps cause some password managers to surrender logins

(Image credit: Shutterstock)

A large number of top password managers may be vulnerable to cyberattack by fake applications, new reports have warned.

Researchers at the University of York found that two out of five password managers gave out customer details when presented with a fake malicious Google app.

While the researchers did not delve into specific details, most of the tested password manager applications had weak criteria of identifying rogue apps, which resulted in this vulnerability being so damaging.

Inadequate security

The researchers added that if hackers are somehow successful in getting victims to install such fake applications, there is a chance they could get easily access to the passwords.

Since many password manager apps do not impose a login limit using a pin or other login, these apps can often be hacked into with the help of a brute force password attack in just over a couple of hours.

Senior author of the study, Dr Siamak Shahandashti from the Department of Computer Science at the University of York, noted that “Because they are gatekeepers to a lot of sensitive information, rigorous security analysis of password managers is crucial. Our study shows that a phishing attack from a malicious app is highly feasible – if a victim is tricked into installing a malicious app it will be able to present itself as a legitimate option on the autofill prompt and have a high chance of success.”

He also suggested that these commercial password managing apps should deploy additional screening measures before sharing password details with other apps and also use better security mechanism to limit login attempts.

While password managers are entrusted to securely remember unique and complex passwords, it becomes imperative for the companies behind these apps to ensure that their applications are safe and are not prone to hack easily. 

Via: IT Pro

Jitendra Soni

Jitendra has been working in the Internet Industry for the last 7 years now and has written about a wide range of topics including gadgets, smartphones, reviews, games, software, apps, deep tech, AI, and consumer electronics.  

Latest in Security
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Latest in News
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
Elayne, Egwene, and Nynaeve dressed regally and on horseback in The Wheel of Time season 3
'There's a reason why we do it': The Wheel of Time showrunner responds to fans who are still upset over the Prime Video show's plot alterations
A mockup of the possible Apple M3 Ultra logo
Performance isn't the only reason you should buy Apple's M3 Ultra Mac Studio - it's reportedly one of the most power-efficient processors too
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
An Nvidia GeForce RTX 4060 Ti
Nvidia could unleash RTX 5060 and 5060 Ti GPUs on PC gamers tomorrow, but there’s no sign of rumored RTX 5050 yet