Is Kaspersky Password Manager safe?

Clean risk

Kaspersky Password Manager reads page DOM and form fields on all sites and routes credential data to the local Kaspersky KPM desktop app via native messaging.

The extension injects content scripts into every HTTP and HTTPS page to serialize the DOM structure and capture form input, including credentials, which are forwarded to a locally installed Kaspersky KPM native host (com.kaspersky.kpm.nm / com.kaspersky.kpm.nmv2). A separate MAIN-world content script intercepts WebAuthn and passkey operations on HTTPS pages, serializing challenge data and routing it through the same native messaging channel so the desktop app can handle passkey creation and sign-in. All data exchange stays on the local machine between the browser extension and the Kaspersky desktop application.

Kaspersky Labv26.0.0.34Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

com.kaspersky.kpm.nm (local native app)com.kaspersky.kpm.nmv2 (local native app)
Updated 17 September 2026mfflbmlbcnhbfbfaafloabcfcfmkpoco