AutoSpill Vulnerability: How Android Autofill Can Expose Passwords
Autofill is one of those features you stop noticing once it works. You tap a login field, your password manager fills it in, and you’re logged in three seconds faster than if you’d typed it yourself.
That convenience is exactly what researchers at IIIT Hyderabad found a way to abuse. They called it AutoSpill, and it showed that the same autofill mechanism protecting your passwords could, under the right conditions, hand them straight to a malicious app instead of the login screen you thought you were typing into.
This guide breaks down what AutoSpill actually is, how the attack works in plain terms, which password managers were affected and which have fixed it, and, more importantly, what you should be doing today to keep your saved credentials safe.
Quick answer: AutoSpill is a 2023 Android vulnerability where a malicious app can trick a password manager’s autofill feature into leaking your saved username and password to the app itself, instead of the legitimate login page it’s supposed to go to, without needing phishing or code injection.
Several major password managers have since shipped fixes, but the underlying risk category (autofill being intercepted inside an app) is still worth understanding, especially with a related but separate clickjacking flaw surfacing in password manager browser extensions in 2025.
What Is the AutoSpill Vulnerability?
AutoSpill was discovered by researchers Ankit Gangwal, Shubham Singh, and Abhijeet Srivastava at the International Institute of Information Technology (IIIT) Hyderabad, and presented at Black Hat Europe 2023 in London.
The vulnerability sits in how Android apps display login pages. Instead of opening your default browser when you tap “Log in with Google” or “Sign in with Facebook” inside an app, most apps use a built-in component called WebView.
It is a mini browser embedded directly in the app, based on the same engine as Chrome. It’s what lets you log into a music app, a shopping app, or a food delivery app using your Google or Facebook account without ever leaving the app.
Password managers hook into this WebView to autofill your saved credentials when that embedded login page loads.
AutoSpill exploits a flaw in that interchange: under certain conditions, the password manager gets “confused” about where exactly to deliver the credentials, and ends up passing them to the underlying app itself, not just the WebView-rendered login form.
A malicious app exploiting this doesn’t need to inject any code or run a phishing scam. It just needs to render a legitimate-looking login screen inside its own WebView and wait for autofill to do the rest.
How the Attack Actually Works
Here’s the flow in simple terms:
- You open an app that offers “Sign in with Google” (or Facebook, Microsoft, etc.).
- The app loads that login page inside its own embedded WebView, rather than your browser.
- Your password manager detects the login fields and offers to autofill your saved credentials.
- Normally, those credentials should land only inside the WebView’s login form, isolated from the app around it.
- With AutoSpill, that isolation breaks. The credentials can leak into the base app’s own memory or fields, meaning the app itself can read your username and password.
No phishing link, no fake app permission prompt, no visible warning. The researchers demonstrated this without JavaScript injection at all; enabling JavaScript injection made the issue worse and affected an even wider set of apps.
Related: Types of Computer Viruses and How to Avoid Them
Which Password Managers Were Affected?
The researchers tested a range of popular Android password managers on Android 10, 11, and 12 devices. Here’s how they stacked up at the time of disclosure and afterwards:
| Password Manager | Vulnerable to AutoSpill (2023 disclosure) | Patch Status |
|---|---|---|
| 1Password | Yes | Acknowledged the issue; shipped a fix to stop native fields from being filled with WebView-only credentials |
| LastPass | Yes | Added a warning pop-up for apps attempting to exploit the flaw, later strengthened |
| Keeper | Yes | Added protective measures to prevent autofill into untrusted apps |
| Enpass | Yes (earlier related flaw) | Patched a related issue back in Enpass 6.8.3 (September 2022) after private disclosure |
| Keepass2Android | Yes | Fix rolled out following disclosure |
| Google Smart Lock | Not vulnerable to this specific flaw | Not applicable |
| Dashlane | Not vulnerable to this specific flaw | Not applicable |
The researchers privately disclosed their findings to Google’s Android security team and to each affected password manager developer before going public (standard responsible-disclosure practice), giving vendors time to ship fixes ahead of or shortly after the Black Hat Europe presentation.
Should you still worry about AutoSpill specifically today? For the exact flaw disclosed in 2023, most major vendors listed above have shipped mitigations. The bigger takeaway isn’t “is this one CVE still open?” It’s that autofill-into-embedded-content is a recurring category of risk, and new variants keep surfacing (more on that below).
AutoSpill vs. Phishing: Why This Was Different
Most credential theft you’ve heard about relies on tricking you: a fake login page, a link in a scam email, a lookalike domain. AutoSpill needed none of that. The “attack surface” was a completely ordinary, expected interaction: tapping “Sign in with Google” inside a normal-looking app, then letting autofill do what it always does.
That’s what made it notable to researchers. It didn’t require you to make a mistake. It exploited trust in a mechanism (autofill inside WebView) that millions of users interact with correctly, every day, without a second thought.
Related: Google’s New Passkey Support Allows You to Sign in Without a Password
A Related, Newer Threat: DOM-Based Extension Clickjacking
It’s worth flagging a separate but conceptually similar issue that surfaced later, so you don’t confuse the two.
In August 2025, researcher Marek Tóth presented a different vulnerability at DEF CON 33 called DOM-based extension clickjacking. Unlike AutoSpill, which targets Android’s in-app WebView autofill, this one targets password manager browser extensions on desktop and mobile browsers.
Attackers use invisible page elements to trick users into triggering autofill on malicious or compromised sites, potentially exposing saved passwords, 2FA codes, and card details.
Tóth’s research reportedly found that 10 of 11 tested extensions were affected at disclosure, including major names like 1Password, Bitwarden, and iCloud Passwords, with patch timelines varying significantly by vendor.
If you use your password manager’s browser extension (not just its mobile app), it’s worth checking whether your extension has been updated since mid-2025 and enabling “autofill on click only” rather than automatic autofill, where that setting is available.
How to Protect Yourself Right Now
You don’t need to abandon your password manager over either of these issues. Password managers are still far safer than reusing or memorising passwords. But a few habits meaningfully reduce your exposure:
- Keep your password manager app and browser extension updated. Patches for both AutoSpill-style and clickjacking-style flaws roll out as app updates. An outdated version is the actual risk, not the password manager category itself.
- Update Android and Chrome/WebView regularly. Google ships fixes to the underlying WebView and Chrome components too; delaying system updates delays your protection.
- Be cautious with “Sign in with Google/Facebook” inside unfamiliar apps. If an app you don’t fully trust asks you to log in via a third-party account, consider opening the service directly in your browser instead of through the app’s embedded login screen.
- Avoid installing apps from outside the Play Store or from developers you don’t recognise. Sideloaded apps are far more likely to be the kind of malicious app this attack scenario depends on.
- Turn off automatic autofill where you can, and use manual/click-to-fill instead, especially for high-value accounts like banking and email.
- Enable two-factor authentication (2FA) on your important accounts. Even if a credential leaks, 2FA stops it from being immediately usable.
- Check your password manager’s release notes after major security disclosures like this one. Reputable vendors publish a clear statement when they patch a known issue.
If you’re using your phone’s built-in autofill rather than a dedicated app, a hardware security key like a YubiKey on Amazon adds a phishing-resistant second factor that isn’t dependent on autofill behaviour at all. It is worth considering for your email and banking logins.
Related: How to Protect Your Bank Account from Hackers?
How to Check If You’re Still at Risk
- Open your password manager app and check its version number against the current release listed on its official website or Play Store page.
- Look at the app’s changelog or security advisories page for any mention of “AutoSpill,” “WebView,” or “autofill isolation” fixes.
- If you also use the browser extension version, repeat the same check for extension updates, and specifically look for mentions of “clickjacking” fixes from mid-to-late 2025 onward.
- If your version predates the relevant fix and no update is available, consider switching to manual copy-paste for sensitive logins until it’s resolved, or moving to a vendor with a confirmed patch.
Myth vs Fact
| Myth | Fact |
|---|---|
| “AutoSpill means my password manager is broken and unsafe to use.” | It exposed a specific flaw in how Android autofill interacts with WebView. Most major vendors have since patched it. Password managers remain far safer than not using one. |
| “This attack requires me to click a phishing link.” | No. Researchers demonstrated it without phishing or JavaScript injection; just a malicious app rendering a normal-looking login screen. |
| “Only shady apps are affected.” | Any app using WebView for third-party sign-in could theoretically be exploited if it were malicious. The risk lies in unfamiliar or sideloaded apps specifically, not mainstream, well-reviewed ones. |
| “If I don’t use autofill, I’m immune to all password manager risks.” | Disabling in-app autofill helps against AutoSpill-style attacks, but the separate DOM-based clickjacking issue targets browser extensions and can trigger even with manual/click-based autofill in some configurations. |
| “Google fixed this at the OS level, so app updates don’t matter.” | Both platform-level and app-level fixes matter here. Keeping your password manager app updated is still necessary even after Android security patches. |
Frequently Asked Questions
AutoSpill is an Android security flaw, disclosed by IIIT Hyderabad researchers in 2023, where a malicious app can capture your saved username and password during autofill, due to a flaw in how Android’s WebView handles credential isolation.
No. Researchers demonstrated the attack without any phishing links or JavaScript injection. It exploits normal autofill behaviour inside an app’s embedded login screen.
1Password, LastPass, Keeper, Enpass, and Keepass2Android were found vulnerable in the original research. Google Smart Lock and Dashlane were not affected by this specific flaw.
Most major affected vendors have shipped mitigations since the 2023 disclosure, including warning pop-ups, blocking autofill into untrusted native fields, and other protective measures. Always confirm you’re on the latest app version.
The original research tested devices running Android 10, 11, and 12.
If your password manager app is updated to a current version and you keep Android and WebView/Chrome updated, the specific flaw disclosed in 2023 should be mitigated. Risk increases mainly with outdated apps or sideloaded software.
The original AutoSpill research focused on username/password credential leakage. Enabling 2FA still adds meaningful protection, since a leaked password alone typically isn’t enough to access an account with 2FA turned on.
No. Security researchers and experts consistently recommend continuing to use a password manager. The alternative, reusing or memorising weak passwords, carries far greater risk. The fix is keeping your password manager updated, not abandoning it.
Check the app’s official changelog, security advisories page, or contact the vendor’s support directly, referencing “AutoSpill” or “Black Hat Europe 2023” disclosure.
The original AutoSpill research specifically targeted Android’s WebView-based autofill mechanism. iOS uses a different autofill architecture, so this particular vulnerability does not directly apply to iPhones.
Apps using “Sign in with Google/Facebook/Microsoft” through an embedded WebView are the relevant category, particularly apps from unfamiliar developers or those installed outside the Play Store.
Change the password for the affected account immediately, enable 2FA if you haven’t already, and check your password manager’s breach-monitoring or “watchtower” feature (if it has one) for compromised credentials.
Google Smart Lock/Google Password Manager was not found vulnerable to the original AutoSpill flaw in the researchers’ testing, though no autofill system is guaranteed risk-free from all future vulnerabilities.
It reduces exposure to autofill-specific attacks like AutoSpill and clickjacking, but at the cost of convenience and potentially encouraging weaker password habits (like reuse) if it pushes users away from password managers altogether. A better balance is keeping software updated and using manual/click-to-fill for sensitive accounts.
Researchers Ankit Gangwal, Shubham Singh, and Abhijeet Srivastava from IIIT Hyderabad presented at Black Hat Europe 2023.
The researchers informed the Android security team as part of responsible disclosure alongside the affected password manager developers before the public presentation.
Reputable mobile security apps can help flag suspicious or malicious apps before installation, which reduces exposure, but the core fix lies in updated password manager software and cautious app installation habits rather than antivirus alone.
It’s a global Android platform vulnerability, not specific to any country or carrier. It affects any Android device running an affected password manager version, though the research team itself was based in Hyderabad, India.
The presentation, titled “AutoSpill: Zero-Effort Credential Stealing from Mobile Password Managers,” was delivered at the Black Hat Europe 2023 conference in London and is listed on Black Hat’s official briefings schedule.
We hope you are interested in our articles and consider following our Facebook, Instagram, and Twitter pages for regular updates.
Also, share this article with your friends and relatives. Bookmark this page for future reference.
Subscribe to our free newsletter to get similar articles and regular updates directly in your Email Inbox.
Subscribe to be the first to learn about new information
Disclosure: If you follow our links to a retailer’s website and make a purchase, we will get an affiliate commission on some, but not all, of the items or services we promote. This will cause no price change for you.
You May Be Interested in Reading:
- Users of Apple and Samsung Should Be Cautious; Warning from CERT-In
- Google’s New Passkey Support Allows You to Sign in Without a Password
- How to Protect Your Bank Account from Hackers?
- What Is Deepfake Technology and How Can You Spot It?
- Chinese Malware, ‘Horse Shell’, Is a Threat to Home and Office Routers







