It’s Cybersecurity Awareness Month! Join our interactive training session, or learn about security and AI from 1Password experts.
Forum Discussion
Jeff_Leigh
4 years agoNew Contributor
Serious autofill bug - filling wrong login
I've been seeing some very strange behavior where logins sometimes get autofilled with the wrong entry and I've been able to replicate at least one cause and it's very concerning.
Have a tab open ...
jmsgwd
4 years agoOccasional Contributor
I'm seeing the same behaviour - for every web site I try and log in to, Autofill now enters my Google credentials rather than those for the web site I'm visiting.
I think this is happening because my Login for Google in 1Password has a linked app: "Google Chrome". This happened because I earlier tried to use Autofill to log in to Google Chrome.app (the browser app itself, not a web site), and 1Password complained that the app was not associated with any Login. One of the options was to update the Login to make the association, and when I did that, "Google Chrome" appeared under Linked apps. This allowed me to successfully use Autofill to log into the Google Chrome browser.
But now 1Password seems to think that every web site I visit in that browser is Google Chrome, and tries to use my Google credentials to log in to the web site!
This seems like a serious bug because my Google credentials have now been exposed to many other unrelated websites. This is especially concerning given that Google is used for Gmail - and therefore functions as "root of trust", since most services use email for their credential reset flows. I do not want a "root of trust" credential sprayed out to dozens of unrelated web sites.
It's great that a fix is on the way - but I don't have time to mess around betas. Nor do I want to go through the hassle of disassociating my Google Login with Google Chrome.app and then figuring out how to re-associate it.
I just want the fix. When is it coming?