{"id":203666,"date":"2022-09-20T11:42:14","date_gmt":"2022-09-20T09:42:14","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=203666"},"modified":"2025-07-01T20:26:36","modified_gmt":"2025-07-02T03:26:36","slug":"chromes-spellchecker-exposing-passwords","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/chromes-spellchecker-exposing-passwords\/","title":{"rendered":"Chrome&#8217;s spellchecker could be exposing your passwords to hackers"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Spellcheckers are an extremely helpful feature that boost productivity by allowing us to quickly and more easily give our typed documents and inputs a proofread and check. Unfortunately, however, <strong>when it comes to in-built web browser spellcheckers there is a security weak point that we need to take into account<\/strong>. Are they checking our passwords and, if so, is anybody able to access that spellchecking data. The answers to these questions seem to be troubling. Let\u2019s check it out.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Google Chrome\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-logo-xl,f_auto\/p\/b2e6d43a-96bf-11e6-a674-00163ed833e7\/965337810\/chrome-Google_Chrome_logo.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Google Chrome<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/chrome.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download Now<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/chrome.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A <a href=\"https:\/\/www.otto-js.com\/news\/article\/chrome-and-edge-enhanced-spellcheck-features-expose-pii-even-your-passwords\">research report<\/a> by JavaScript cybersecurity specialists otto-js has unearthed some worrying findings about the spellchecker features on the Google Chrome and Microsoft Edge web browsers. Yes, they are helping us boost our productivity but they are also<strong> sharing our password details with websites <\/strong>whenever we are trying to log into your web accounts and services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the report, <strong>there are three primary websites and services that are exposed to this vulnerability<\/strong>. These are Office 365, Alibaba \u2013 Cloud Service, and Google Cloud \u2013 Secret Manager. AWS \u2013 Secret Manager and LastPass were also vulnerable to the issue, but they have already fully mitigated the issue according the otto-js report.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Josh Summit at otto-js had this to say about this rather novel vulnerability:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>\u201cSome of the largest websites in the world have exposure to sending Google and Microsoft sensitive user PII, including username, email, and passwords, when users are logging in or filling out forms [\u2026] If &#8216;show password&#8217; is enabled, the feature even sends your password to their 3rd-party servers.\u201d<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, until this vulnerability is mitigated by the affected sites there is nothing you as a user can do to safeguard your web usage apart from <strong>disabling your browser\u2019s spellchecker<\/strong>. In truth, however, this isn\u2019t a massive price to pay as although spellcheckers are useful on web browsers, they are nowhere near as useful as they are on word processors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In other cybersecurity news, <a href=\"https:\/\/microsoft-word.en.softonic.com\/articles\/fake-word-docs-contain-almost-undetectable-malware\" target=\"_blank\" rel=\"noreferrer noopener\">scammers have been circulating fake Word docs packed with almost undetectable malware<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Spellcheckers are an extremely helpful feature that boost productivity by allowing us to quickly and more easily give our typed documents and inputs a proofread and check. Unfortunately, however, when it comes to in-built web browser spellcheckers there is a security weak point that we need to take into account. Are they checking our passwords &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/chromes-spellchecker-exposing-passwords\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Chrome&#8217;s spellchecker could be exposing your passwords to hackers&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9073,"featured_media":203693,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[2378],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-203666","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionchrome"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/203666","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=203666"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/203666\/revisions"}],"predecessor-version":[{"id":323174,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/203666\/revisions\/323174"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/203693"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=203666"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=203666"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=203666"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=203666"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=203666"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=203666"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}