
Critical N-able Passportal Bug Lets Malicious Sites Access Password Vaults
N-able has patched a critical vulnerability in its Passportal browser extension that could have allowed any malicious website or embedded iframe to steal long-lived authentication tokens and gain persistent access to a victim’s decrypted password vault. The flaw, tracked as CVE-2026-15580, affected Passportal extension version 3.49.5 on Google Chrome and Microsoft Edge. N-able released version […]
The post Critical N-able Passportal Bug Lets Malicious Sites Access Password Vaults appeared first on Cyber Security News.