Researchers show how Chrome extensions can steal plaintext passwords for popular sites such as Gmail, Cloudflare, Facebook, etc

…most importantly, websites should not be storing their passwords in the HTML DOM in plain text. See https://www.bleepingcomputer.com/news/security/chrome-extensions-can-steal-plaintext-passwords-from-websites/ Steve Gibson’s discussion at https://www.grc.com/sn/SN-938-Notes.pdf Original Research Report and Remedies at https://arxiv.org/pdf/2308.16321.pdf…