Executive brief
Avira Password Manager is a tool used to securely store and automatically fill login credentials for websites. A security flaw when using the software with the Mozilla Firefox browser could allow a malicious website to trick the manager into filling a user's sensitive credentials into a hidden, unauthorized part of the page. This could lead to the theft of usernames and passwords without the user's knowledge.
Technical details
An information disclosure vulnerability exists in the Avira Password Manager extension when used with Mozilla Firefox. The root cause is incorrect autofill field selection logic, which fails to properly isolate parent page fields from cross-origin iframes. A remote attacker can host a malicious page that embeds a target site within an iframe; if the user has credentials saved for the parent site, the extension may incorrectly autofill those credentials into fields controlled by the attacker's iframe. This bypasses the Same-Origin Policy (SOP) for credential handling, allowing for the silent extraction of sensitive login data. The vulnerability affects users on Windows, macOS, and Linux.
Affected products
- Avira Password Manager All versions used with Mozilla Firefox on Windows, macOS, and Linux
Timeline
- 2026-06-12: disclosed: Initial publication of CVE-2026-12068
- 2026-06-12: advisory