bitwarden / bitwarden/clients

Launch website from MacOS App did not ask for master password in browser

Open
#13,625 1 comment 0 reactions 0 assignees View on GitHub
bug desktop
Dominant language
TypeScript
Stars
13.8k
Forks
2k
Avg merge
3d 9h
Merged PRs (30d)
397

Description

### Steps To Reproduce

1. Running MacOS client, I searched for my bank's entry
2. Clicked on launch
3. This Opens the bank login window in Duckduckgo, (default browser)
4. Clicked on username field, and the bitwarden entry for my user pops up
5. Clicked on the entry in the pop up, and the login name and password are filled in WITHOUT asking for the master password

### Expected Result

I should have gotten "This action is protected. To continue, please re-enter your master password to verify your identity." I do if I use Chrome, and I do if I click on show password in the MacOS app.

PS I know the passwords need to be accessible via the API, but do we really need to expose even a list of my accounts via the app. I would prefer to require a password every time I open the bitwarden window, while not requiring the password when using the duckduckgo browser, unless the entry is protected.

### Actual Result

Filled in username and password without asking for master password

### Screenshots or Videos

_No response_

### Additional Context

_No response_

### Operating System

macOS

### Operating System Version

15.3.1

### Installation method

Mac App Store

### Build Version

Version 2025.2.0 (37899)

### Issue Tracking Info

- [x] I understand that work is tracked outside of GitHub. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the flow on macOS 15.3.1 with the Mac App Store build: launch the bank entry in DuckDuckGo, then use the Bitwarden autofill pop-up. Done means protected entries trigger the stated master-password prompt before username and password are filled, matching the behavior seen in Chrome and when showing a password in the macOS app.

Written by the indexing model from the issue text.

Assessment

Tech stack
electron, macos, typescript
Domain
authentication, desktop, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.