Skip to main content

Your browser might be filling in hidden fields and giving away your secrets

A hand on a laptop in a dark surrounding.
Image used with permission by copyright holder
It seems like you can’t go online lately without running into a new way to get infected with malware or have your identity stolen. And sometimes, it seems like there’s nothing you can do to avoid exposing yourself to trouble.

One of the more difficult traps to avoid is a phishing site, which presents itself as a legitimate page while requesting account and other sensitive information. Now, there’s apparently a browser vulnerability that can enter information on phishing sites without your knowledge and without your needing to do a thing, as ZDNet reports.

Recommended Videos

Basically, as security researcher Viljami Kuosmanen discovered, some browsers’ autofill functionality will fill out even hidden fields on sites. The Finnish hacker posted sample code on Github demonstrating how he could grab user information such as credit card numbers, expiration dates, and security codes with hidden fields automatically filled in when accessing a page using Google’s Chrome browser.

Various browsers are affected by the vulnerability, with Apple’s Safari and the Opera browser joining Chrome. Daniel Veditz, a Mozila security researcher, posted on Twitter that Firefox doesn’t suffer from the issue because only fields that users can actually click on can be autofilled by that browser.

Please enable Javascript to view this content

At this point, there doesn’t appear to be any solution to the problem other than turning of autofill functionality in your chosen browser. For example, to turn off Autofill in Chrome, go to the menu, select Settings, then “Show advanced settings …,” the uncheck “Enable Autofill to fill out web forms in a single click.”

It’s up to browser developers to fix the bug for good, of course. In the meantime, if you decide to leave autofill turned on due to its general convenience factor, you’ll need to be even more diligent about making sure you’re only visiting known and trusted websites.

Mark Coppock
Mark Coppock is a Freelance Writer at Digital Trends covering primarily laptop and other computing technologies. He has…
LG unveils a monster 5K ‘bendable’ OLED gaming monitor
An UltraGear curved monitor on a desk in front of a window.

Ahead of CES 2025, LG has announced new extra-large additions to its line of UltraGear GX9 OLED gaming monitors: one being a massive, 45-inch display with a bendable panel, and the other, a 39-inch "smart" gaming monitor with webOS built-in.

Let's start with the big boy, though, because it has an impressive "world's first" designation behind it. It's the first 5K OLED monitor on the market, featuring a resolution of 5120 x 2160 -- also known as 5K2K. Not only is it the first OLED monitor in general to have a 5K resolution but it's also the first gaming monitor to launch with this higher resolution, normally reserved for high-end creator monitors like the Apple Studio Display.

Read more
Intel quietly opens preorders on new Arrow Lake CPUs
Fingers holding an Intel 285K.

With CES 2025 right around the corner, most of us expect the big announcements to arrive in a week -- but some companies are already teasing new products. In Intel's case, the manufacturer plans to add more CPUs that might compete against some of the best processors. To that end, Intel has now announced preorders for new Arrow Lake CPUs, but most of us can't get our hands on them yet.

As spotted by VideoCardz, Intel China announced that preorders for the Core Ultra 200 non-K CPUs are opening today, with availability planned for January 13. These CPUs will presumably just be non-overclockable versions of existing Arrow Lake chips, such as the Core Ultra 9 285K. In its announcement, Intel teases "new architecture" and "better power consumption."

Read more
It was a horrible year for data breaches. These were the 5 worst in 2024
Person typing on a computer keyboard.

This was a historically awful year in data breaches. We saw some record-breaking breaches this year that got the attention of the public, involving hackers accessing some very sensitive information, including Social Security numbers, credit card numbers, and more.

Let's look back at the worst cybersecurity incidents of the year and let them encourage all of us to be as prudent as we can with our activity online.
National Public Data, where hackers claim to steal 2.9 billion personal records
Background check company National Public Data, also known as Jerico Pictures, suffered one of the worst data breaches when hackers allegedly stole 2.9 billion personal records. The class action lawsuit claimed that hackers leaked critical data such as full names, addresses, and relative information to the dark web.

Read more