A cybersecurity researcher has uncovered zero-day clickjacking affecting eleven major password managers, potentially exposing tens of millions of users to credential theft.

The research, conducted by security expert Marek Tóth, reveals that attackers can exploit the vulnerabilities to steal credit card details, personal information, login credentials , and even two-factor authentication (2FA) codes.
The new attack technique, dubbed "DOM-based Extension Clickjacking," is a significant evolution of traditional web-based clickjacking attacks.
Unlike conventional methods, this technique manipulates user interface (UI) elements that are inserted into web page DOM structures by password manager extensions. In this way, they remain invisible and clickable at the same time.
See also: CodeRabbit: Vulnerability allowed access to 1 million repositories
The attack works through malicious scripts that hide the extensions' UI elements, mainly with opacity adjustments and DOM overlay techniques.
When users encounter seemingly legitimate elements, such as cookie acceptance banners or CAPTCHAs, on compromised websites, a single click can trigger the autofill of hidden forms with stored sensitive data .
Password managers: Extensive vulnerability
Tóth tested eleven popular password managers, including 1Password, Bitwarden, LastPass, Dashlane, and Keeper. The results were alarming: all of the managers were vulnerable to at least one variant of the DOM-based Extension Clickjacking technique.

The vulnerabilities affect approximately 40 million active installations across the Chrome Web Store, Firefox Add-ons, and Edge Add-ons.
Six of the nine administrators were vulnerable to credit card data, while eight of the ten could be exploited to extract stored personal information.
Perhaps most worryingly: ten of the eleven password managers were vulnerable to credential theft, including passwords used for two-factor authentication.
See also: Chrome vulnerability allows malicious code execution
Following responsible disclosure in April 2025, several vendors have implemented fixes. Dashlane, Keeper, NordPass, ProtonPass , and RoboForm have successfully updated their extensions .
However, major players such as 1Password, Bitwarden, LastPass, iCloud Passwords, Enpass, and LogMeOnce remain vulnerable until August 2025 (approximately 32.7 million active installations affected).
The persistence of these vulnerabilities in widely used password managers highlights the complexity of protecting browser extensions.
Unlike traditional clickjacking, which can be mitigated through HTTP headers, new DOM-based attacks require more comprehensive defense measures at the extension level.
Password managers typically autofill credentials not only on the exact domain they were stored on but also on all subdomains, significantly expanding the attack surface.
This means that an attacker who finds Cross-Site Scripting (XSS) vulnerabilities in any subdomain can potentially steal the user's main account credentials through clickjacking techniques.
See also: SAP NetWeaver: Public Exploit for chained vulnerabilities

Protection
While full fixes require action from extension developers, users can take some protective measures . For Chromium -based browsers , experts recommend setting extensions' access to websites as "on click" instead of automatic, giving users manual control over the autofill feature.
The research also highlights the importance of regularly updating password manager extensions, as several vendors have already released fixes after the vulnerability was disclosed.
Users should verify that they are using the latest version and consider disabling autofillif available. This may reduce convenience, but is necessary for security.
The discovery of these vulnerabilities highlights the ever-evolving nature of security threats on the web and the need for continued research into the extension ecosystem.
As password managers become increasingly central to digital security practices, ensuring their resilience against sophisticated attacks is critical to protecting sensitive data.
