Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomePassword Manager Extension
Findings · 3
MEDIUM FINDINGS · 3
  1. 01URL parameter ?fskeyLoginId=<id> on any https page triggers automatic credential autofill into page-discovered inputs without user interaction or origin check
  2. 02Legacy fallback POSTs master password and saved credentials in cleartext to http://localhost:24166 (loopback HTTP, not TLS) when native messaging is unavailable
  3. 03Content script scans every https page (all_frames) for login forms via DOMSubtreeModified-driven heuristic and reports URL+title to background for credential lookup
OTHER EXTENSIONS

Is Password Manager Extension safe?

Medium risk

No summary available.

F-Secure Corporationv5.0.43Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.f-secure.PasswordManagerExtension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact