Security researchers have developed a new attack, which they have dubbed AutoSpill, to steal account credentials on devices during the autofill process.
See also: Android Auto: Discover how to personalize its UI

In a presentation at the Black Hat Europe, researchers from the International Institute of Information Technology and Technology (IIIT) in Hyderabad said their tests showed that most password managers for Android are vulnerable to AutoSpill, even if there is no JavaScript.
Android apps often use the WebView control to display content , such as login pages within the app, rather than redirecting users to the main browser, which would be more cumbersome on small-screen devices.
Password managers on Android use the platform's WebView framework to automatically type in a user's account credentials when an app loads the login page for services like Apple, Facebook, Microsoft , or Google.
The researchers reported that it is possible to exploit weaknesses in this process to capture auto-filled credentials in the application , even without any JavaScript input. If JavaScript inputs are enabled, the researchers state that all Android password managers are vulnerable to the AutoSpill attack.
More specifically, the AutoSpill problem stems from Android's failure to enforce or clearly define responsibility for the secure handling of auto-filled data, which can be leaked or recorded by the hosting application.
See also: Android: Tempts users to install the latest update
In an attack scenario, a malicious application offering a login form can capture the user's credentials without leaving any evidence of the breach. Additional technical details about the AutoSpill attack are available in the researchers' slides from the Black Hat Europe event.
The researchers tested AutoSpill on a selection of password managers on Android 10, 11, and 12 and found that 1Password 7.9.4, LastPass 5.11.0.9519, Enpass 6.8.2.666, Keeper 16.4.3.1048, and Keepass2Android 1.09c-r0 are vulnerable to attacks due to the use of Android autofill.

Google Smart Lock 13.30.8.26 and DashLane 6.2221.3 took a different technical approach to the autofill process. No sensitive data to the hosting application unless JavaScript embedding was used.
The researchers disclosed their findings to affected software vendors and the Android security team, sharing their recommendations for addressing the issue. Their report was acknowledged as valid, but no details about the fix plans were shared.
One of the main ways to prevent cyberattacks on Android devices is to update the operating system and applications on a regular basis. Software companies are constantly upgrading products to fix any security vulnerabilities and protect devices from attacks. Therefore, it is important to regularly check for available updates and install them promptly.
See also: New Fleckpe Android malware detected on Google Play
Another important way to prevent this is to install a reliable antivirus software on your device. Antivirus programs can detect and remove malware, thus protecting your device from potential attacks. Choose a reliable antivirus program from a reputable provider and update it frequently to keep your device secure
Additionally, paying attention to installing apps from trusted sources is crucial. Avoid installing apps from unknown developers or from untrusted sources, as they may contain malware. Prefer the Google Play Store or other official app distribution platforms and read reviews and ratings before installing.
Finally, paying attention to the security of network connections is also important. Avoid connecting to open and unsecured Wi-Fi, as these can expose your device to risks. Prefer secure Wi-Fi networks and use tools like VPN to encrypt your connection and protect your personal data.
Source: bleepingcomputer
