PhilippC / PhilippC/keepass2android

AutoSpill vulnerability in Keepass2Android

Open
#2,478 24 comments 6 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
C#
Stars
6.2k
Forks
478
Avg merge
1h 4m
Merged PRs (30d)
2

Description

Checks
  • I have read the FAQ section, searched the open issues, and still think this is a new bug.
Describe the bug you encountered:

A recent presentation at Black Hat discusses a new vulnerability that affects password managers on Android when using WebView autofill. This vulnerability reportedly also affects Keepass2Android. More details can be found in the article below:

Vulns in Android WebView, Password Managers Can Leak User Credentials
https://www.darkreading.com/cyberattacks-data-breaches/android-vulnerability-leaks-credentials-from-password-managers-

Describe what you expected to happen:

No response

What version of Keepass2Android are you using?

1.09e-r7

Which version of Android are you on?

13

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Begin by reading the linked Dark Reading article and reviewing the Android WebView autofill path in Keepass2Android. The issue names no files, tests, or entry points; completion would require determining whether version 1.09e-r7 is affected and documenting or implementing a verified mitigation.

Written by the indexing model from the issue text.

Assessment

Tech stack
android
Domain
mobile, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.