Click Studios, the company behind the password management solution Passwordstate, has released security updates to address an authentication bypass vulnerability.

The issue, which has not yet received a CVE identifier, has been addressed in Passwordstate version 9.9 (Build 9972), released on August 28, 2025. The Australian company said it fixed a vulnerability that allows “potential authentication bypass when a carefully crafted URL is used against the Emergency Access page of the core Passwordstate products.” The latest release also includes improved protections against potential clickjacking attacks targeting the password managerwhen users visit compromised websites.
See also: Cisco Nexus 3000 and 9000 Series: Vulnerability allows DoS attacks
These safeguards are likely a response to findings by security researcher Marek Tóth, who recently described a technique called Document Object Model (DOM)-based extension clickjacking. Many popular password manager browser add-ons were found to be vulnerable to this tactic.
“A single click anywhere on an attacker-controlled website could allow attackers to steal user data (credit card details, personal data, login credentials, including TOTP),” Tóth said. “The new technique is general and can be applied to other types of extensions.”
According to Click Studios, the password manager is used by 29,000 customers and 370,000 security and IT professionals, including global enterprises, government organizations, financial institutions , and Fortune 500 companies.

Passwordstate: New patch by Click Studios and the ongoing gamble with security
Click Studios’ recent update to Passwordstate isn’t just a typical bug fix. Rather, it’s a reminder that password managers — despite their critical role in everyday digital life — are constantly being targeted by researchers and attackers. Authentication bypass via crafted URLs and clickjacking threats in browser extensions highlight once again that tools that are supposed to enhance our security can, under certain circumstances, become weak links.
See also: Passkeys: SquareX reveals significant vulnerability
What makes the case even more worrying is the broader dimension of the technique revealed by Marek Tóth. The DOM-based extension clickjacking method does not only concern Passwordstate, but potentially any password manager with a browser add-on. This means that the issue is not isolated; it is structural and concerns the entire password management solutions. In other words, users do not only have to worry about the security of their software, but also about how it interacts with the browser and the web ecosystem.
However, the responsibility does not lie solely with the provider. Organizations using password managers should adopt a more layered security strategy. Regular updates, evaluating third-party extensions, restricting access rights, and incorporating zero trust controls are not “optional extras,” but necessary defenses in a landscape where even the most trusted platforms can be compromised.
See also: 28,000+ Citrix instances vulnerable to zero-day vulnerability

Passwordstate remains one of the most widespread tools on the market. However, the new vulnerability and the patch that followed remind that in security there are no final solutions: each update is also a reminder that the battle with attackers is continuous and asymmetric.
Passwordstate: Previous security incidents
This revelation comes about four years after a supply chain breach that allowed attackers to compromise the software update mechanism to deploy malware capable of harvesting sensitive information from compromised systems.
Additionally, in December 2022, Click Studios patched multiple security vulnerabilities in Passwordstate, including an authentication bypass for the Passwordstate API (CVE-2022-3875, CVSS score: 9.1) that could have been used by a remote attacker to obtain a user's passwords in plain text.
