LastPass scrambles to fix another major flaw – once again spotted by Google's bugfinders
For most of us, Saturday morning is a time for a lie in, a leisurely brunch, or maybe taking the kids to the park. But for some it's bug-hunting time.
Tavis Ormandy, a member of Google's crack Project Zero security team, was in the shower and thinking about LastPass – after finding a number of flaws in the password manager over the past week. Then he had an epiphany and "realized how to get codeexec in LastPass 4.1.43," he said, and filed a bug report. The timing couldn't have been worse for LastPass engineers. They spent last weekend sorting out Tavis' other bug finds, and now it looked like they'd be back in the office again this weekend. LastPass has now confirmed that the new find is an issue and they are working on it.