CVE-2025-65203

7.1

KeePassXC · KeePassXC-Browser

KeePassXC-Browser versions through 1.9.9.2 are vulnerable to credential exfiltration because they autofill credentials into sandboxed iframes that can be accessed by attacker-controlled scripts.

Executive summary

A critical vulnerability in the KeePassXC-Browser extension allows unauthenticated attackers to exfiltrate stored credentials by exploiting improper autofill behavior in sandboxed environments.

Vulnerability

This vulnerability occurs because the extension fails to restrict credential autofill operations within browser-sandboxed iframes, allowing malicious scripts embedded in those frames to intercept and exfiltrate sensitive data. This flaw can be triggered by an unauthenticated attacker who directs a user to a compromised page.

Business impact

The exploitation of this vulnerability directly results in the theft of user credentials stored within the browser extension. Given the CVSS score of 7.1, the risk is high as it facilitates unauthorized access to potentially all accounts managed by the user, leading to significant data compromise and potential account takeover.

Remediation

Immediate Action: Users should immediately disable the KeePassXC-Browser extension or exercise extreme caution by avoiding untrusted websites until an official patch is released by the vendor.

Proactive Monitoring: Security teams should monitor browser-based authentication logs for unusual access patterns and restrict the use of browser extensions in high-security environments.

Compensating Controls: Implement browser-level security policies and Content Security Policies (CSP) to limit the execution of untrusted scripts within iframes where possible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability poses a significant risk to individual and organizational credential security. Administrators must treat this as a high-priority issue and monitor the KeePassXC-Browser GitHub repository for the release of a patched version. Until a fix is deployed, consider restricting the use of this extension on systems that handle sensitive corporate credentials.

Sources