Keeweb: [Privacy Issue] Shortcut pastes password into any app in foreground

Created on 6 Mar 2017  路  1Comment  路  Source: keeweb/keeweb

  • what were your actions?
  1. Chrome full screen on mac. Press Ctrl+Alt+T to fill password.
  2. Keeweb shows popup to select website comes.
  3. Select website
  4. Popup disappears
  5. Slack is open behind the popup. This app gets selected and focus goes into that app.
  6. Keeweb fills password into the chatbox. Voila, embarrassingly enough everyone has your username and password now.
  7. Go change your password on the website
  • what was expected?

Only paste the username/password if the selected app is the one where the action was initiated

  • app version

Version 1.3.3 (52701af)

  • your user-agent (from Settings/Help section)

Mac App

  • does it happen on Demo or New database?
    Yup.
  • please, open dev tools in your browser and attach output log from Console tab
    (if you are using desktop app, devtools can be opened from Settings/General/Advanced)
    N/A
bug security

Most helpful comment

The proposed fix is to get window title again and run auto-type only after a comparison.

>All comments

The proposed fix is to get window title again and run auto-type only after a comparison.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

PercussiveRepair picture PercussiveRepair  路  4Comments

ericbn picture ericbn  路  4Comments

Akeboshiwind picture Akeboshiwind  路  3Comments

antelle picture antelle  路  3Comments

facutopa picture facutopa  路  3Comments