Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes

A critical vulnerability in N-able Passportal’s Chrome and Microsoft Edge browser extensions could allow a malicious website or embedded iframe to steal an organization’s entire password vault, including live two-factor authentication codes. Tracked as CVE-2026-15580, the issue received a CVSS v4.0 base score of 9.4 and affected Passportal extension version 3.49.5. N-able released version 3.49.6 […]

This article has been indexed from Cyber Security News

Read the original article: