LogoLogo
リリースノート
リリースノート
  • Keeperからの最新情報
  • KEEPER SECURITY
    • 最新情報ブログ
    • セキュリティに関する注意事項
      • Black Hat EU 2023
      • CVE-2022-21449
    • トラブルシューティング
      • 最初にお読みください
      • KeeperFillブラウザ拡張機能
      • ボルト&デスクトップアプリ
      • iPhone & iPad
      • Android
      • エンタープライズプラン管理者
  • デスクトップ
    • ボルト (保管庫)
      • プレビュー版リリース
      • ボルトリリース 17.1.1
      • ボルトリリース 17.1.0
      • ボルトリリース 17.0.0
      • ボルトリリース 16.11.3
      • ボルトリリース 16.11.2
      • ボルトリリース 16.11.1
      • ボルトリリース 16.11.0
      • ボルトリリース 16.10.12
      • 以前のバージョン
        • ボルトリリース 16.10.10
        • ボルトリリース 16.10.9
        • ボルトリリース 16.10.8
        • ボルトリリース 16.10.6
        • ボルトリリース 16.10.5
        • ボルトリリース 16.10.3
        • ボルトリリース 16.10.2
        • ボルトリリース 16.10.0
        • Vault Release 16.9.0
        • Vault Release 16.8.9
        • Vault Release 16.8.6
        • Vault Release 16.8.5
        • Vault Release 16.8.4
        • Vault Release 16.8.3
        • Vault Release 16.8.2
        • Vault Version 16.8.0
        • Vault Version 16.7.2
        • Vault Version 16.7.1
        • Vault Version 15.0.13
        • Vault Version 15.0.12
        • Vault Version 15.0.11
        • Vault Version 15.0.10
        • Vault Version 15.0.9
        • Vault Version 15.0.8
        • Vault Version 15.0.7
        • Vault Version 15.0.6
        • Vault Version 15.0.5
        • Vault Version 15.0.4
        • Vault Version 15.0.3
        • Vault Version 15.0.1
        • Vault Version 15.0.0
        • Vault Version 14.14.1
        • Vault Version 14.14.0
        • Vault Version 14.13.3
        • Vault Version 14.13.2
        • Vault Version 14.13.0
        • Vault Version 14.13.1
        • Vault Version 14.13.0
        • Vault Version 14.12.5
        • Vault Version 14.12.2
        • Vault Version 14.12.1
        • Vault Version 14.12.0
        • Vault Version 14.10.4
        • Vault Version 14.10.3
        • Vault Version 14.10.2
        • Vault Version 14.10.1
        • Vault Version 14.10.0
        • Vault Version 14.9.12
        • Vault Version 14.9.10
        • Vault Version 14.9.9
        • Vault Version 14.9.8
        • Vault Version 14.9.7
        • Vault Version 14.9.5
        • Vault Version 14.9.4
        • Vault Version 14.9.2
        • Vault Version 14.9.1
        • Vault Version 14.9.0
        • Vault Version 14.7.0
        • Vault Version 14.5.1
        • Vault Version 14.5.0
        • Vault Version 14.4.7
        • Vault Version 14.4.1
        • Vault Version 14.4.0
        • Vault Version 14.3.0
        • Vault Version 14.2.1
        • Vault Version 14.2.0
        • Vault Version 15.0.14
        • Vault Version 15.0.15
        • Vault Version 15.0.16
        • Vault Version 15.0.18
        • Vault Version 15.1.0
        • Vault Version 15.2.0
        • Vault Version 16.0.0
        • Vault Version 16.0.1
        • Vault Version 16.1.0
        • Vault Version 16.2.0
        • Vault Version 16.2.3
        • Vault Version 16.2.5
        • Vault Version 16.2.6
        • Vault Version 16.3.0
        • Vault Version 16.3.1
        • Vault Version 16.4.0
        • Vault Version 16.4.2
        • Vault Version 16.4.3
        • Vault Version 16.4.6
        • Vault Version 16.5.0
        • Vault Version 16.6.0
        • Vault Version 16.7.0
        • Vault Release 16.8.1
    • パスワードインポートツール
      • Importer Version 15.1.4
      • Importer Version 15.1.3
      • Importer Version 15.1.1
      • Importer Version 15.1.0
      • Importer Version 15.0.1
      • Importer Version 15.0.0
      • Importer Version 14.0.6
      • Importer Version 12.0.6
      • Importer Version 12.0.5
    • KeeperChat
      • KeeperChat クライアントリリース 17.0
      • KeeperChat クライアントリリース 5.8.7
      • KeeperChat クライアントリリース 5.8.5
      • KeeperChat Client Release 5.3.2
      • KeeperChat Client Release 5.3.1
      • KeeperChat Client Release 5.3.0
      • KeeperChat Client Release 5.2.0
      • KeeperChat Client Release 5.1.0
      • KeeperChat Client Release 5.0.1
      • KeeperChat Client Release 5.0.0
      • KeeperChat Client Release 4.5.0
      • KeeperChat Client Release 4.4.0
      • KeeperChat Client Release 4.3.1
      • KeeperChat Client Release 4.3.0
      • KeeperChat Client Release 4.2.0
      • KeeperChat Client Release 4.1.0
      • KeeperChat Client Release 4.0.0
      • KeeperChat Client Release 3.1.8
      • KeeperChat Client Release 3.1.7
      • KeeperChat Client Release 3.1.6
      • KeeperChat Client Release 3.1.5
      • KeeperChat Client Release 3.1.4
      • KeeperChat Client Release 3.1.3
      • KeeperChat Client Release 3.1.2
      • KeeperChat 2.2.0
  • ブラウザ拡張機能
    • Chrome, Edge, Firefox, Safari
      • プレビュー版リリース
      • ブラウザ拡張機能 Ver 17.1.0
      • ブラウザ拡張機能 Ver 17.0.1
      • ブラウザ拡張機能 Ver 17.0
      • ブラウザ拡張機能 Ver 16.11.0
      • ブラウザ拡張機能 Ver 16.10.0
      • ブラウザ拡張機能 Ver 16.9.1
      • ブラウザ拡張機能 Ver 16.9.0
      • ブラウザ拡張機能 Ver 16.8.1
      • ブラウザ拡張機能 Ver 16.8.0
      • ブラウザ拡張機能 Ver 16.7.6
      • ブラウザ拡張機能 Ver 16.7.5
      • ブラウザ拡張機能 Ver 16.7.4
      • 過去のリリース
        • Browser Extension Version 16.6.3
        • Browser Extension Version 16.6.2
        • Browser Extension Version 16.6.1
        • Browser Extension Version 16.6.0
        • Browser Extension Version 16.5.3
        • Browser Extension Version 16.5.0
        • Browser Extension Version 16.4.16
        • Browser Extension Version 16.4.14
        • Browser Extension Version 16.4.13
        • Browser Extension Version 16.4.12
        • Browser Extension Version 16.4.8
        • Browser Extension Version 16.4.7
        • Browser Extension Version 16.4.6
        • Browser Extension Release 16.4.4
        • Browser Extension Release 16.4.3
        • Browser Extension Version 16.4.2
        • Browser Extension Version 16.4.1
        • Browser Extension Version 16.4.0
        • Browser Extension Version 16.2.0
        • Browser Extension Version 16.1.1
        • Browser Extension Version 16.1.0
        • Browser Extension Version 16.0.3
        • Browser Extension Version 16.0.0
        • Browser Extension Version 15.3.9
        • Browser Extension Version 15.3.8
        • Browser Extension Version 15.3.7
        • Browser Extension Version 15.3.5
        • Browser Extension Version 15.3.4
        • Browser Extension Version 15.3.3
        • Browser Extension Version 15.1.2
          • Browser Extension Version 15.1.4
        • Browser Extension Version 15.1.0
        • Browser Extension Version 15.0.5
        • Browser Extension Version 15.0.4
        • Browser Extension Version 15.0.3
        • Browser Extension Version 15.0.2
        • Browser Extension Version 15.0.1
        • Browser Extension Version 15.0.0
        • Browser Extension Version 14.2.2
        • Browser Extension Version 14.2.1
        • Browser Extension Version 14.2.0
        • Browser Extension Version 14.1.2
        • Browser Extension Version 14.1.1
        • Browser Extension Version 14.1.0
        • Browser Extension Version 14.0.6
        • Browser Extension Version 14.0.5
        • Browser Extension Version 14.0.2
        • Browser Extension Version 14.0.0
        • Browser Extension Version 14.0
        • Browser Extension Version 12.6.4
        • Browser Extension Version 12.6.0
        • Browser Extension Version 12.5.8
        • Browser Extension Version 12.5.7
        • Browser Extension Version 12.5.6
        • Browser Extension Version 12.5.2
        • Browser Extension Version 12.5.1
        • Browser Extension Version 12.5.0
        • Browser Extension Version 12.4.1
        • Browser Extension Version 12.4.0
        • Browser Extension Version 12.3.7
        • Browser Extension version 12.3.6
        • Browser Extension Version 12.3.5
        • Browser Extension Version 12.3.4
        • Browser Extension Version 12.3.1
        • Browser Extension Version 12.3.0
        • Browser Extension Version 12.2.7
      • Browser Extension Version 15.3.0
    • Safari (レガシー版)
      • 今後の展開について
      • Safari Extension Release 16.2.5
      • Safari Extension Release 16.0.0
      • Safari Extension Release 15.2.0
      • Safari Extension Release 15.1.0
      • Safari Extension Release 15.0.14
      • Safari Extension Release 15.0.12
      • Safari Extension Release 15.0.11
      • Safari Extension Release 15.0.10
      • Safari Extension Release 15.0.0
      • Safari Extension Release 14.14.0
      • Safari Extension Version 14.13.3
      • 以前のバージョン
        • Safari Extension Version 14.13.2
        • Safari Extension Version 14.13.0
        • Safari Extension Version 14.12.2
        • Safari Extension Version 14.10.2
        • Safari Extension Version 14.10.0
        • Safari Extension Version 14.1.0
        • Safari Extension Version 14.0.4
        • Safari Extension Release 14.0.2
        • Safari Extension Version 14.0.0
    • IE (レガシー版)
      • IE Extension Release 15.0.5
      • IE Extension Release 15.0.3
      • IE Extension Release 15.0.3
      • IE Extension Release 15.0.2
      • IE Extension Release 15.0.1
      • IE Extension Release 14.0.0
      • IE Extension Version 12.4.0
      • IE Extension Version 12.2.3
      • IE Extension Version 12.2.2
      • IE Extension Version 12.2.1
      • IE Extension Version 12.1.0
  • モバイル
    • Android
      • Android バージョン 17.1.0
      • Android バージョン 17.0.0
      • Android バージョン 16.10.10
      • Android バージョン 16.10.0
      • Android バージョン 16.9.0
      • Android バージョン 16.8.60
      • Android バージョン 16.8.50
      • Android バージョン 16.8.40
      • Android バージョン 16.8.30
      • Android バージョン 16.8.25
      • Android バージョン 16.8.20
      • Android バージョン 16.8.10
      • Android Version 16.6.60
      • 以前のバージョン
        • Android Version 16.5.0
        • Android Version 16.4.3
        • Android Version 16.4.2
        • Android Version 16.4.1
        • Android Version 16.4.0
        • Android Version 16.0.5
        • Android Version 16.0.0
        • Android Version 15.5.10
        • Android Version 15.5.0
        • Android Version 15.4.0
        • Android Version 15.3.0
        • Android Version 15.0.12
        • Android Version 15.0.10
        • Android Version 15.0.1
        • Android Version 15.0.0
        • Android Version 14.5.60.1
        • Android Version 14.5.53.3
        • Android Version 14.5.51.1
        • Android Version 14.5.50.4
        • Android Version 14.5.40
        • Android Version 14.5.31
        • Android Version 14.5.3
        • Android Version 14.5.2
        • Android Version 14.5.1
        • Android Version 14.5.0
        • Android Version 14.4.10
        • Android Version 14.4.0
        • Android Version 14.3.5
        • Android Version 14.3.4
        • Android Version 14.3.0
        • Android version 14.2.3
        • Android Version 14.2.2
        • Android Version 14.2.0
        • Android Version 14.1.3
        • Android Version 14.1.2
        • Android Version 14.1.1
      • Android Version 15.0.2
    • iOS
      • iOS TestFlight (テストフライト)
      • iOS バージョン 17.2.0
      • iOS バージョン 17.1.0
      • iOS バージョン 17.0.0
      • iOS バージョン 16.12.0
      • iOS バージョン 16.11.1
      • iOS バージョン 16.11.0
      • iOS バージョン 16.10.7
      • iOS バージョン 16.10.5
      • iOS バージョン 16.10.2
      • iOS バージョン 16.10.1
      • iOS バージョン 16.10.0
      • iOS バージョン 16.9.6
      • iOS Version 16.9.0
      • 以前のバージョン
        • iOS Version 16.8.1
        • iOS Version 16.8.0
        • iOS Version 16.7.0
        • iOS Version 16.6.5
        • iOS Version 16.6.0
        • iOS Version 16.5.0
        • iOS Version 16.4.0
        • iOS Version 16.0.3
        • iOS Version 16.0
        • iOS Version 15.5.0
        • iOS Version 15.4.1
        • iOS Version 15.4.0
        • iOS Version 15.3.0
        • iOS Version 15.0.3
        • iOS Version 15.0.2
        • iOS Version 15.0.1
        • iOS Version 15.0.0
        • iOS Version 14.11.1
        • iOS Version 14.11.0
        • iOS Version 14.10.2
        • iOS Version 14.10.0
        • iOS Version 14.9.1
        • iOS Version 14.9.0
        • iOS Version 14.8.2
        • iOS Version 14.8.1
        • iOS Version 14.8.0
        • iOS Version 14.7.2
        • iOS Version 14.7.1
        • iOS Version 14.7.0
        • iOS Version 14.6.1
        • iOS Version 14.6.0
        • iOS Version 14.5.0
        • iOS Version 14.4.0
        • iOS Version 14.3.1
        • iOS Version 14.3.0
        • iOS Version 14.2.1
        • iOS Version 14.2.0
        • iOS Version 14.1.0
  • エンタープライズ
    • 管理コンソール
      • プレビュー版リリース
      • 管理コンソール 17.2.2
      • 管理コンソール 17.2.0
      • 管理コンソール 17.1.0
      • 管理コンソール 17.0.0
      • 管理コンソール 16.20.0
      • 管理コンソール 16.19.0
      • 管理コンソール 16.18.7
      • 管理コンソール 16.18.0
      • 管理コンソール 16.17.1
      • 管理コンソール 16.17.0
      • 過去のリリース
        • 管理コンソール 16.16.0
        • 管理コンソール 16.15.0
        • 管理コンソール 16.13.2
        • 管理コンソール 16.12.0
        • Admin Console 16.11
        • Admin Console 16.10.3
        • Admin Console 16.9.0
        • Admin Console 16.7.1
        • Admin Console 16.7
        • Admin Console 16.6
        • Admin Console 16.2
        • Admin Console 16.1.1
        • Admin Console 16.1.0
        • Admin Console 16.0.0
        • Admin Console 15.3.3
        • Admin Console 15.3.0
        • Admin Console 15.0.5
        • Admin Console 15.0.4
        • Admin Console 15.0.3
        • Admin Console 15.0.1
        • Admin Console 15.0.0
        • Admin Console 14.5.0
        • Admin Console 14.4.2
        • Admin Console 14.4.1
        • Admin Console 14.4.0
        • Admin Console 14.3.5
        • Admin Console 14.3.4
        • Admin Console 14.3.3
        • Admin Console 14.3.2
        • Admin Console 14.3.1
        • Admin Console 14.3.0
        • Admin Console 14.2.6
        • Admin Console 14.2.5
        • Admin Console 14.2.4
        • Admin Console 14.2.3
        • Admin Console 14.2.0
        • Admin Console 14.1.2
        • Admin Console 14.1.0
        • Admin Console 14.0.3
        • Admin Console 14.0.2
        • Admin Console 14.0.1
        • Admin Console 14.0
        • Admin Console 13.3
        • Admin Console 13.2
        • Admin Console 13.1
      • Admin Console 15.0.2
    • Keeperコネクションマネージャー
      • KCM バージョン 2.19.3
      • KCM バージョン 2.19.2
      • KCM バージョン 2.19.0
      • KCM バージョン 2.18.3
      • KCM バージョン 2.18.2
      • KCM バージョン 2.18.1
      • KCM Version 2.17.0
      • KCM Version 2.16.1
      • KCM Version 2.16.0
      • KCM Version 2.15.1
      • KCM Version 2.15.0
      • 過去のリリース
        • Glyptodon Version 2.8.0
        • Glyptodon Version 2.8.1
        • KCM Version 2.9.0
        • KCM Version 2.9.3
        • KCM Version 2.9.4
    • Keeperシークレットマネージャー
      • 2025年1月
      • 2024年12月
      • 2024年11月
      • 2024年9月
      • 2024年7月
      • 2024年6月
      • 以前のアップデート
    • Keeperゲートウェイ
      • プレビュー版
      • Keeperゲートウェイ v1.5.2
      • Keeperゲートウェイ v1.5.1
      • Keeperゲートウェイ v1.5.0
      • Keeperゲートウェイ v1.4.3
    • オンプレミスSSOコネクト
      • オンプレミスSSOコネクト 17.0.0
      • オンプレミスSSOコネクト 16.0.8
      • オンプレミスSSOコネクト 16.0.7
      • SSO Connect Version 16.0.4
      • SSO Connect Version 16.0.3
      • SSO Connect Version 16.0.2
      • SSO Connect Version 16.0.1
      • SSO Connect Version 16.0.0
      • SSO Connect Version 15.1.1
      • SSO Connect Version 15.1.0
      • SSO Connect Version 15.0.1
      • SSO Connect Version 15.0.0
      • SSO Connect Version 14.2.1
      • SSO Connect Version 14.2.0
      • SSO Connect Version 14.1.3
      • SSO Connect Version 14.1.2
      • SSO Connect Version 14.1.1
      • SSO Connect Version 14.1
      • SSO Connect Version 14.0
      • SSO Connect Version 12.0.5
    • ADブリッジ
      • アップグレード手順
      • ブリッジ バージョン17.0.0
      • ブリッジ バージョン16.1.5
      • 過去のリリース
        • ブリッジ バージョン16.1.4
        • Bridge Version 16.1.3
        • Bridge Version 16.1.1
        • Bridge Version 16.1.0
        • Bridge Release 16.0.0
        • Bridge Release 15.1.0
        • Bridge Version 15.0.2
        • Bridge Version 15.0.1
        • Bridge Version 15.0.0
        • Bridge Version 14.1.1
        • Bridge Version 14.1.0
        • Bridge Version 14.0.0
        • Bridge Version 13.1.2
        • Bridge Version 13.1.1
        • Bridge Version 13.0.1
        • Bridge Version 13.1.0
        • Bridge Version 13.0.0
        • Bridge Version 10.5.4
        • Bridge Version 10.5.3
    • SSO証明書
      • 2023年クラウドSSO証明書更新
      • On-Prem SSO Certificate Renewal
    • Siemens Typer
  • バックエンド
    • バックエンドAPI
      • バックエンドAPI 17.6
      • バックエンドAPI 17.5
      • バックエンドAPI 17.4
      • バックエンドAPI 17.3.5
      • バックエンドAPI 17.3.2
      • バックエンドAPI 17.3.1
      • バックエンドAPI 17.3.0
      • バックエンドAPI 17.2.0
      • バックエンドAPI 17.1.0
      • バックエンドAPI 16.12.0
      • Backend API Version 16.10.0
      • Backend API Version 16.9.14
      • Backend API Version 16.9.13
      • Backend API Version 16.9.12
      • Backend API Version 16.9.11
      • Backend API Version 16.9.10
      • 過去のリリース
        • Backend API Version 16.9.9
        • Backend API Version 16.5.2
        • Backend API Version 16.5.1
        • Backend API Version 16.4.1
        • Backend API Version 16.4
        • Backend API Version 16.3.6
        • Backend API Version 16.3.4
        • Backend API Version 16.3.2
        • Backend API Version 16.3.0
        • Backend API Version 16.2.15
        • Backend API Version 16.2.14
        • Backend API Version 16.2.12
        • Backend API Version 16.2.8
        • Backend API Version 16.2.0
        • Backend API Version 16.1.3
        • Backend API Version 16.1.0
        • Backend API Version 16.0.8
        • Backend API Version 16.0.6
        • Backend API Version 16.0.4
        • Backend API Version 16.0.2
        • Backend API Version 16.0.0
        • Backend API Version 15.2.4
        • Backend API Version 15.2.2
        • Backend API Version 15.2.0
        • Backend API Version 15.1.2
        • Backend API Version 15.1.1
        • Backend API Version 15.1.0
        • Backend API Version 15.0.32
        • Backend API Version 15.0.31
        • Backend API Version 15.0.30
        • Backend API Version 15.0.29
        • Backend API Version 15.0.28
        • Backend API Version 15.0.27
        • Backend API Version 15.0.26
        • Backend API Version 15.0.25
        • Backend API Version 15.0.24
        • Backend API Version 15.0.23
        • Backend API Version 15.0.22
        • Backend API Version 15.0.21
        • Backend API Version 15.0.20
        • Backend API Version 15.0.19
        • Backend API Version 15.0.18
        • Backend API Version 15.0.17
        • Backend API Version 15.0.16
        • Backend API Version 15.0.15
        • Backend API Version 15.0.14
        • Backend API Version 15.0.12
        • Backend API Version 15.0.11
        • Backend API Version 15.0.10
        • Backend API Version 15.0.9
        • Backend API Version 15.0.7
        • Backend API Version 14.12.6
        • Backend API Version 14.12.5
        • Backend API Version 14.12.1
        • Backend API Version 14.12.0
        • Backend API Version 14.11.0
        • Backend API Version 14.10.0
        • Backend API Version 14.9.12
        • Backend API Version 14.9.0
        • Backend API Version 14.8.2
        • Backend API Version 14.8.1
        • Backend API Version 14.7.16
        • Backend API Version 14.7.11
        • Backend API Version 14.7.10
        • Backend API Version 14.7.9
        • Backend API Version 14.7.8
        • Backend API Version 14.7.7
        • Backend API Version 14.7.6
        • Backend API Version 14.7.4
        • Backend API Version 14.7.0
        • Backend API Version 14.6.0
        • Backend API Version 14.5.2
        • Backend API Version 14.5.0
        • Backend API Version 14.4.0
        • Backend API Version 14.3.0
        • Backend API Version 14.2.0
  • 開発者向けツール
    • コマンダー
      • コマンダー v17.0.11
      • コマンダー v17.0.8
      • コマンダー v16.11.11
      • コマンダー v16.11.10
      • コマンダー v16.11.9
      • 過去のリリース
        • Commander 16.6.13
        • Commander 16.6.12
        • Commander 16.6.11
        • Commander 16.6.10
        • Commander 16.6.9
        • Commander 16.6.7
        • Commander 16.6.6
        • Commander v16.6.5
        • Commander v16.6.3
        • Commander v16.6.1
        • Commander v16.6.0
        • Commander v16.4
          • Commander v16.4.9
          • Commander v16.4.8
          • Commander v16.4.7
          • Commander v16.4.6
          • Commander v16.4.5
          • Commander v16.4.4
          • Commander v16.4.3
          • Commander 16.4.2
          • Commander 16.4.1
          • Commander v16.4.0
        • Commander v16.3
          • Commander 16.3.3
          • Commander 16.3.2
          • Commander v16.3.1
          • Commander v16.3.0
        • Commander v16.2
          • Commander v16.2.3
          • Commander v16.2.2
          • Commander v16.2.1
          • Commander v16.2.0
        • Commander v16.5
          • Commander v16.5.18
          • Commander v16.5.17
          • Commander v16.5.15
          • Commander v16.5.14
          • Commander v16.5.13
          • Commander v16.5.12
          • Commander v16.5.11
          • Commander v16.5.10
          • Commander v16.5.9
          • Commander v16.5.7
          • Commander v16.5.6
          • Commander v16.5.5
          • Commander v16.5.3
          • Commander v16.5.2
          • Commander v16.5.1
    • オートメーター
      • オートメーター 17.0.0
      • オートメーター 3.2.1
      • Automator Version 3.2
      • Automator Version 3.1
      • Automator Version 2.2.1
      • Automator Version 2.2.0
      • Automator Version 2.1
      • Automator Version 1.0.6
      • Automator Version 1.0.5
      • Automator Version 1.0.4
      • Automator Version 1.0.3
    • Docs Home
Powered by GitBook
On this page
  • Security Updates to Keeper Browser Extension
  • Background
  • Reporting Sequence
  • Summarized Findings in the Security Researcher’s Report
  • How to Update
Export as PDF
  1. ブラウザ拡張機能
  2. Chrome, Edge, Firefox, Safari
  3. 過去のリリース

Browser Extension Version 12.3.7

Released on July 12, 2019

PreviousBrowser Extension Version 12.4.0NextBrowser Extension version 12.3.6

Last updated 2 years ago

Security Updates to Keeper Browser Extension

Background

‌This update addresses two reported potential security vulnerabilities affecting websites that have installed an IFrame from a malicious source. For the exploit to be realized, a sequence of conditions would be required which in turn, would impact the Keeper Browser Extension. No customer has reported being affected by this issue. Despite the fact that this is an extremely rare and improbable situation, Keeper takes all reported bugs seriously.

Within five hours of receiving the security researcher’s vulnerability report, Keeper Security’s development and security team released a new version of the Keeper Browser Extension to eliminate the risk associated with the reported vulnerabilities. The Keeper Browser Extension has been submitted to the app stores for publication. The version number for Chrome, Firefox and Edge is 12.3.7. The Safari version is 14.0.4.

Special thanks to for the discovery and documentation of this issue.

Reporting Sequence

The security researcher’s findings were reported via Keeper's Bugcrowd Public Vulnerability Disclosure Program today, marked on July 12, 2019 at 2:51 PM PST and 2:53PM PST. Discussions between Keeper’s Security Team and the security researcher occurred within one hour of receiving the researcher’s report. The issues disclosed in the report were accepted, validated and submitted for publication to the app stores, within five hours of receipt.

Summarized Findings in the Security Researcher’s Report

1. Autofill in a sandboxed, untrusted, malicious IFrame

The security researcher reported that a user’s website login credentials could potentially be autofilled into a website containing a malicious sandboxed IFrame to capture the user’s login credentials for that specific site.

Keeper’s Security Team’s Response:

In order for this potential vulnerability to result in an exploit of the user’s password for a website, the following conditions would need to exist:

  1. The website owner / developer (e.g. xyz.com) must explicitly embed a malicious iFrame into their website’s HTML served from the same origin or another domain origin with "sandbox" property set that contains a login form.

  2. The Keeper user would require a password stored in their Keeper Vault for xyz.com.

  3. The Keeper user would need to visit the subject website, xyz.com.

  4. The Keeper user would need to enable Autofill for the subject website, xyz.com, if prompted by the user's Keeper software. If the user previously clicked "Yes" on the Autofill prompt for site xyz.com, the user would not be prompted again.

  5. Keeper then fills the password for the saved xyz.com site into the malicious iFrame which contains the sandbox property.

2. Autofill in untrusted malicious IFrame from different domain

The security researcher reported that a user’s website login credentials could potentially be autofilled into a website containing a malicious IFrame, served from a different domain, to capture the user’s login credentials for that specific site.

In order for this potential vulnerability to result in an exploit of the user’s password for a website, the following conditions would need to exist:

  1. The website owner / developer (e.g. xyz.com) must explicitly embed a malicious IFrame into their website's HTML served from an untrusted origin (e.g. somesite.com) that contains a login form, or the website owner has embedded a 3rd party library from an untrusted origin which injects a malicious IFrame.

  2. The Keeper user would require a password stored in their Keeper Vault for xyz.com.

  3. The Keeper user would need to visit the subject website, xyz.com.

  4. The Keeper user would need to enable Autofill for the subject website, xyz.com, if prompted by the user's Keeper software. If the user previously clicked "Yes" on the Autofill prompt for site xyz.com, the user would not be prompted again.

  5. Keeper then fills the password for the saved xyz.com site into the malicious IFrame served from a different domain.

It would be extremely unlikely and unusual for a website owner to purposely inject an untrusted IFrame into their page source from a different origin. Despite this, Keeper Security’s development team made the security improvements to its browser extension to prevent an autofill operation under the two reported scenarios.

How to Update

‌The Keeper Browser Extension will auto-update from each respective app store (i.e. Mac Store, Chrome Web Store, Firefox Add-ons and Microsoft Edge Store).

All security and vulnerability reports are managed and submitted to Keeper's Bugcrowd Public Vulnerability Disclosure program at:

We appreciate the detailed report, reproduction steps and supporting documentation provided by the security researcher, Alesandro Ortiz. If you have any questions regarding this update please email security@keepersecurity.com. Alesandro's website is .

Alesandro Ortiz
https://AlesandroOrtiz.com
https://bugcrowd.com/keepersecurity