Skip to main content

Your browser might be filling in hidden fields and giving away your secrets

A hand on a laptop in a dark surrounding.
Image used with permission by copyright holder
It seems like you can’t go online lately without running into a new way to get infected with malware or have your identity stolen. And sometimes, it seems like there’s nothing you can do to avoid exposing yourself to trouble.

One of the more difficult traps to avoid is a phishing site, which presents itself as a legitimate page while requesting account and other sensitive information. Now, there’s apparently a browser vulnerability that can enter information on phishing sites without your knowledge and without your needing to do a thing, as ZDNet reports.

Basically, as security researcher Viljami Kuosmanen discovered, some browsers’ autofill functionality will fill out even hidden fields on sites. The Finnish hacker posted sample code on Github demonstrating how he could grab user information such as credit card numbers, expiration dates, and security codes with hidden fields automatically filled in when accessing a page using Google’s Chrome browser.

Various browsers are affected by the vulnerability, with Apple’s Safari and the Opera browser joining Chrome. Daniel Veditz, a Mozila security researcher, posted on Twitter that Firefox doesn’t suffer from the issue because only fields that users can actually click on can be autofilled by that browser.

At this point, there doesn’t appear to be any solution to the problem other than turning of autofill functionality in your chosen browser. For example, to turn off Autofill in Chrome, go to the menu, select Settings, then “Show advanced settings …,” the uncheck “Enable Autofill to fill out web forms in a single click.”

It’s up to browser developers to fix the bug for good, of course. In the meantime, if you decide to leave autofill turned on due to its general convenience factor, you’ll need to be even more diligent about making sure you’re only visiting known and trusted websites.

Editors' Recommendations

Mark Coppock
Mark has been a geek since MS-DOS gave way to Windows and the PalmPilot was a thing. He’s translated his love for…
How to create a bibliography in Word on Windows and Mac
A family using the computer to browse Fios internet together.

A bibliography is an important part of any well-structured college essay, dissertation, article, or other researched writing sample. It lets your readers know what sources you used as building blocks for your work, and isn’t too difficult to make without a template tool. Still, if you’d like to skip a few steps, there’s a terrific bibliography generator built right into Microsoft Word.

Read more
The unsung hero behind the modernization of Windows laptops
New Surface Laptop Studio 2 with a Surface Pen.

The large, multitouch trackpad was once synonymous with the MacBook. And starting in 2015, that has also included a haptic feedback trackpad, which simulates a physical click via a motorized engine under the surface. It was quite the revelation, and despite some initial skepticism, it really took off.

As you would expect, Apple held a patent on the technology, enjoying a five-year start ahead of other laptops. The first attempts at haptic feedback trackpads on Windows laptops weren't promising either.

Read more
How to create a Memoji on a Mac
Memoji creation screen in Messages on Mac.

Using emojis is a great way to add flair and personality to what would just be a plain ole’ text message. But if you’re an Apple devotee, you’ll also be able to liven your chats up with Memojis. Introduced on iOS 12, Memojis are custom avatars that you make in your likeness. Choose from numerous clothing, facial hair, and other cosmetic filters to dial in your appearance. When finished, your Memojis can be used with a few iOS apps, including Messages and FaceTime.

Read more