Phishing Attacks against Password Manager Browser Extensions

Claudio Anliker, Daniele Lain, Srdjan Capkun

34th USENIX Security Symposium · Day 1

This article delves into a critical security research paper titled "Phishing Attacks against Password Manager Browser Extensions," presented by Claudio Anliker, Daniele Lain, and Srdjan Capkun from ETH Zurich at USENIX Security. The research uncovers a novel and highly effective phishing vector that specifically targets the master passwords of browser extension-based password managers. Unlike conventional phishing attempts that direct users to fake login pages for services, this attack exploits a fundamental design weakness in how browser extensions render their user interfaces, making it difficult for users to distinguish between a legitimate password manager UI and a malicious imitation embedded within an attacker-controlled website.

AI review

Solid empirical work that quantifies a real attack vector most security folks hand-wave about. The 31% average success rate across ~450 PM users is the number that matters. Not a novel *concept* — we've known extension UI confusion is bad — but the scale of the study and the demographic breakdown make this a cite-able reference going forward.