most major password managers vulnerable to 0-day clickjacking attack

Matt Johansen
Matt Johansen
Published on 20.08.2025

Subscribe to my free weekly newsletter: https://vulnu.com/subscribe

Major Password Managers Exposed: New Clickjacking Vulnerability!

Researchers uncovered zero day Clickjacking flaws in top password managers like Bitwarden, 1Password, LastPass, and more.

In this episode, I break down what Clickjacking is, how these vulnerabilities can leak your data, and why some companies chose not to fix them.

Socket - https://socket.dev/blog/password-manager-clickjacking

Marek toth defcon research - https://marektoth.com/blog/dom-based-extension-clickjacking/

00:00 Shocking Headline: ClickJacking Vulnerabilities Exposed
00:37 Defcon Talk Highlights: Major Password Managers at Risk
03:00 Understanding ClickJacking: Traditional vs. DOM-Based
04:17 Research Findings: Vulnerabilities and Vendor Responses
08:13 Security vs. Usability: The Debate
10:30 Final Thoughts and Viewer Engagement

MY OTHER SOCIALS
🌎Website / Blog https://www.vulnu.com/
📰Newsletter / https://www.vulnu.com/subscribe/
📷 Instagram / https://www.instagram.com/mattjayy
🐦Twitter / https://x.com/mattjay
🔗LinkedIn / https://www.linkedin.com/in/matthewjohansen/
🦋 Bsky / https://bsky.app/profile/mattjay.com

ABOUT ME
In case we haven’t met yet, Hi, I'm Matt, your friendly neighborhood security guy 👋 I'm a computer security veteran who has helped defend startups, the biggest financial companies in the world, and everything in between. Through my socials, free newsletter, and YouTube channel, I bring you curated cybersecurity news and personal and professional growth with a mental health cherry on top.

Runtime 00:11:29

COMMENTS: 0