USENIX Security2024Top-tier venue
Exploiting Leakage in Password Managers via Injection Attacks
Andrés Fábrega, Armin Namavari, Rachit Agarwal, Ben Nassi, Thomas Ristenpart
Abstract
This work explores injection attacks against password managers. In this setting, the adversary (only) controls their own application client, which they use to"inject"chosen payloads to a victim's client via, for example, sharing credentials with them. The injections are interleaved with adversarial observations of some form of protected state (such as encrypted vault exports or the network traffic received by the application servers), from which the adversary backs out confidential information. We uncover a series of general design patterns in popular password managers that lead to vulnerabilities allowing an adversary to efficiently recover passwords, URLs, usernames, and attachments. We develop general attack templates to exploit these design patterns and experimentally showcase their practical efficacy via analysis of ten distinct password manager applications. We disclosed our findings to these vendors, many of which deployed mitigations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8f6f6e92-c284-423c-b002-3a9281decf07Cited by top-tier papers4
- Vault Raider: Stealthy UI-based Attacks Against Password Managers in Desktop EnvironmentsAndrea Infantino, Mir Masood Ali, Kostas Solomos, Jason PolakisNDSS 2026 · 1 citation
- Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password ManagersMatteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. PatersonUSENIX Security 2026
- Mitigating Injection Attacks against E2EE Applications via View-Based PartitioningAndrés Fábrega, Samuel Breckenridge, Armin Namavari, Thomas RistenpartUSENIX Security 2025
- Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed ChannelsFabian Bäumer, Marcus BrinkmannCCS 2026
Builds on10
- Better managed than memorized? Studying the Impact of Managers on Password Strength and ReuseSanam Ghorbani Lyastani, Michael Schilling, Sascha Fahl, Michael Backes et al.USENIX Security 2018 · 63 citations
- Dancing on the Lip of the Volcano: Chosen Ciphertext Attacks on Apple iMessageChristina Garman, Matthew Green, Gabriel Kaptchuk, Ian Miers et al.USENIX Security 2016 · 62 citations
- On the Security of Cracking-Resistant Password VaultsMaximilian Golla, Benedict Beuscher, Markus DürmuthCCS 2016 · 54 citations
- Sigstore: Software Signing for EverybodyZachary Newman, John Speed Meyers, Santiago Torres-AriasCCS 2022 · 35 citations
- Searching Encrypted Data with Size-Locked IndexesMin Xu, Armin Namavari, David Cash, Thomas RistenpartUSENIX Security 2021 · 10 citations
Related papers
- Credential Extraction Attacks Against Compromised Credential Checking Services of Password ManagersYihe Duan, Ding Wang, Yutong LiS&P 2026 · 1 citation
- Phishing Attacks against Password Manager Browser ExtensionsClaudio Anliker, Daniele Lain, Srdjan CapkunUSENIX Security 2025
- Injection Attacks Against End-to-End Encrypted ApplicationsAndrés Fábrega, Carolina Ortega Pérez, Armin Namavari, Ben Nassi et al.S&P 2024 · 9 citations
- Phishing Attacks on Modern AndroidSimone Aonzo, Alessio Merlo, Giulio Tavella, Yanick FratantonioCCS 2018 · 68 citations
- Security Analysis of Master-Password-Protected Password Management ProtocolsYihe Duan, Ding Wang, Yanduo FuS&P 2025
