Google Project Zero’s Tavis Ormandy found a severe vulnerability in the LastPass password manager. The vulnerability allows an attacker to communicate with the add-on through malicious code. LastPass, however, has released a patch for the vulnerability. The company says the problem has now been fixed, but it’s not clear whether attackers had used the vulnerability before OrMandy’s disclosure. Another researcher found another security researcher to disclose another issue he found in LastPass that was fixed about a year ago.”]
Source: https://www.govinfosecurity.com/lastpass-patches-password-manager-vulnerability-a-9299