Skip to main content
  1. Home
  2. Computing
  3. News

Hackers may have stolen the master key to another password manager

Add as a preferred source on Google

The best password managers are meant to keep all your logins and credit card info safe and secure, but a major new vulnerability has just put users of the KeePass password manager at serious risk of being breached.

In fact, the exploit allows an attacker to steal a KeePass user’s master password in plain text — in other words, in an unencrypted form — simply by extracting it from the target computer’s memory. It’s a remarkably simple hack, yet one that could have worrying implications.

An app used to extract a user's master password from the KeePass password manager app.
The KeePass master password vulnerability discovered by security researcher ‘vdohney.’ The extracted master password (minus the first two characters) is shown at the end of the “Combined” line. Bleeping Computer

Password managers like KeePass lock up all your login info to keep it safe, and all that data is sealed behind a master password. You enter your master password to access everything stored in your vault, which makes it a valuable target for hackers.

Recommended Videos

As reported by Bleeping Computer, the KeePass vulnerability was discovered by security researcher ‘vdohney,’ who published a proof-of-concept (PoC) tool on GitHub. This tool is able to extract almost the entire master password (except the first one or two characters) in readable, unencrypted form. It can even do this if KeePass is locked and, potentially, if the app is closed altogether.

That’s because it extracts the master password from KeePass’s memory. As the researcher explains, this can be obtained in a variety of ways: “It doesn’t matter where the memory comes from — can be the process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys) or RAM dump of the entire system.”

The exploit exists thanks to some custom code KeePass uses. When you enter your master password, you do so in a custom box called SecureTextBoxEx. Despite the name, it turns out this box is not so secure after all, since every character typed into the box essentially leaves a leftover copy of itself in the system memory. It’s these remnant characters that the PoC tool finds and extracts.

A fix is coming

Unsplash

The one caveat to this security breach is it requires physical access to the machine from which the master password is to be extracted. But that’s not necessarily always a problem — as we’ve seen in the LastPass exploit saga, hackers can gain access to a target’s computer using vulnerable remote access apps installed on the computer.

If a target computer was infected with malware, it could be configured to dump KeePass’s memory and send both it and the app’s database back to the hacker’s own server, allowing the threat actor to extract the master password in their own time.

Fortunately, KeePass’s developer says a fix is incoming, with one of the possible remedies being to insert random dummy text into the app’s memory that would obfuscate the password. The fix is not expected to be released until June or July 2023, which could be a painful wait for anyone nervous about their master password being leaked. However, the developer has also released a beta version of the fix, which can be downloaded from the KeePass website.

The vulnerability just goes to show that even seemingly secure apps like password managers can be breached, and it’s not the first time a serious weakness has been found in KeePass. If you want to keep yourself safe from online threats like this latest exploit, avoid downloading apps or opening files from unknown senders, steer clear of questionable websites, and use an antivirus app. And, of course, never share your password manager’s master password with anyone.

Alex Blake
Alex Blake has been working with Digital Trends since 2019, where he spends most of his time writing about Mac computers…
Qualcomm is set to ratchet up chip prices in September, and your next gadget upgrade could bear the brunt
The price hike could touch every Snapdragon-powered device category.
The new Qualcomm Snadragon 8 Elite Gen 5

I want you to sit with this for a second. Qualcomm, the company whose Snapdragon chips sit inside your Android phone and tablet, your Windows laptop, your Meta smart glasses, your Galaxy Watch, and your wireless earbuds, reportedly sent a letter to every major customer telling them prices are going up by double digits. 

The price hike will be in effect from September 1, 2026, a recent Bloomberg report claims. Essentially, all the companies placing their chip orders after that will pay a higher price. 

Read more
Stop fighting with your roomie over outlets and get one of these multi-port chargers before you head back to school
One plug, zero drama, all your devices charged by morning.
Satechi ChargeView

Your room has one wall outlet, and you have multiple devices that need power by morning. Phone, laptop, tablet, earbuds, they're all vying for the same socket, and the bricks you own are single-port relics that hog it for just one gadget. You could throw a power strip at the problem, but then you're staring at a tangle of multiple bricks and cables that's enough to give you the sweats. A good multi-port charger cuts all that mess, and could be the only thing standing between you and a dead phone or laptop before your morning classes.

Back-to-school season is a smart time to buy one. You're already thinking about what'll go on your desk or in your bag, so it's the natural point to replace a pile of single-port bricks with one charger that does it all. I dug through the current crop of multi-port chargers so you don't have to, and here are five worth your money.

Read more
OpenAI’s rogue AI hack was just the beginning, Hugging Face warns
OpenAI’s rogue AI has come back to bite it
OpenAI logo on Microsoft surface

Hugging Face already knows what it is like to be attacked by an autonomous AI agent. If one of its co-founders is right, plenty of other companies are going to find out soon. Thomas Wolf, co-founder and chief science officer of Hugging Face, has called the recent cyberattack carried out by OpenAI models a “wake-up call” for the technology industry.

Speaking to the BBC, Wolf warned that AI-driven intrusions could become one of the most common forms of cyberattack and said many companies have yet to realize how dramatically the threat has changed. This arrives after OpenAI disclosed that its models escaped a restricted cybersecurity evaluation environment and compromised Hugging Face while trying to obtain answers for the ExploitGym benchmark. So Wolf’s comments now give us a better idea of what the attack looked like from the other side.

Read more