Be careful if useste Last Pass: Tavis Ormandy, one of its most prolific members teamGoogle's Project Zero has revealed a new security issue in LastPass.
Ormandy said there was a exploit but has not made it public at the moment. Let's remind that Google Project Zero researchers report the vulnerabilities first to the directly interested companies developing the affected products. Companies have 90 days to insure their product, usually by developing a new version, otherwise researchers are releasing the exploit.
The information they are few and far between so far, as Ormandy made them available via Twitter:
Oops, new bug in Last Pass affecting version 4.1.42 (Chrome&FF). RCE if you use “Binary Component”, otherwise they can steal codes access. I am preparing a full report.
Oops, new LastPass bug that affects 4.1.42 (Chrome & FF). RCE if you use the "Binary Component", otherwise can steal pwds. Full report on way. pic.twitter.com/y92vm3Ibxd
- Tavis Ormandy (@taviso) March 20, 2017
Reports last version of LastPass for Google Chrome and Firefox (4.1.42 version), and that exploit can be used for remote code execution or password theft.
Later, he revealed that he has a full operational exploit that does not display messages in Windows, and is just two lines of code. He also noted that exploit could also work on other platforms.
Wrote and quick exploit for another LastPass vulnerability. Only affects version on https://t.co/lGcefN9YXM (3.3.2), report on way. ¯_ (ツ) _ / ¯ pic.twitter.com/AgjASiQMfJ
- Tavis Ormandy (@taviso) March 16, 2017
LastPass also posted a Twitter message stating that she was aware of the issue and that she was working to find a solution.
We are aware of the report by @taviso and our team has put a workaround in place while working on a resolution. Stay tuned for updates.
- LastPass (@LastPass) March 21, 2017
Shortly after, the company published a second message stating that the issue was resolved.
The issue mentioned by Tavis Ormandy has been resolved. We will provide additional clarifications to our blog soon.
According to the tweet, if you use the Last Pass application, you do not have to do anything except waiting for the announcement of the solution that corrects vulnerability from the company.