Imagine you're the IT admin for a 50-person company. You've done everything right: you deployed a reputable password manager, you're enforcing credential policies, and you sleep reasonably well at night. Then you find out that for up to 100 days, every password in that vault was silently readable by any website — or any malicious iframe embedded in one — that your browser happened to visit.
That's not a hypothetical. That's the N-Able Passportal browser extension vulnerability, and it's a wake-up call for every IT admin holding the keys to a small business.
What Actually Happened with Passportal
The Passportal Chrome and Edge extension contained a critical flaw rated CVSS 9.4. When the extension was active, it exposed the decrypted contents of the password vault to any web page or embedded iframe in the browser — no authentication required from the attacking site. A malicious ad, a compromised third-party script, or a poisoned iframe on an otherwise legitimate page could have silently read every credential stored in that vault.
According to Security News, the vulnerability exposed password vault master keys and the flaw persisted for an extended window before being patched — with the product's cloud-based architecture leaving residual risk even after the fix was deployed. For an IT admin managing credentials for an entire organization, that's not a bug. That's a full organizational compromise waiting to happen.
Here's the part that should keep you up at night: you may never know if you were hit. There's no loud alarm when an iframe reads your vault. No ransomware note. No login alert. The exfiltration is silent, and the attacker can sit on those credentials for weeks or months before using them.
'Patched' Doesn't Mean 'Safe'
The instinct after a patch is to exhale. Don't.
When a credential vault has been potentially exposed for up to 100 days, patching the extension closes the hole — but it does nothing about credentials that may have already been copied. Every password that lived in that vault during the exposure window should be treated as compromised until rotated. That's not paranoia. That's incident response.
This pattern is increasingly common across the tools IT admins trust most. According to The Hacker News, a Rust supply chain attack recently poisoned packages with 245 million downloads by compromising a maintainer account — the same threat model as a trusted browser extension silently leaking credentials. The attack surface isn't the sketchy software. It's the trusted software.
And the broader identity threat environment makes this worse. According to The Hacker News, a Microsoft Entra ID flaw rated CVSS 10.0 is being actively exploited in the wild, allowing remote code execution. A credential vault leak doesn't happen in isolation — it happens inside an environment where identity-layer attacks are already at peak intensity.
We've covered this pattern before in our breakdown of what happens after a password manager breach and how to run a 24-hour incident response. The playbook applies here directly.
Three Things You Need to Do This Week
1. Audit Every Browser Extension in Your Environment
Browser extensions run with elevated permissions inside the browser context. Most IT admins have no inventory of what extensions are installed across their fleet. Start there.
- Pull a list of all installed extensions across managed endpoints
- Flag any extension with access to "read and change all your data on websites you visit" — that's the permission class that made the Passportal flaw exploitable
- Remove extensions that aren't business-critical
- Block extension installation via policy (Group Policy or MDM) except from an approved list
This isn't optional hygiene anymore. Browser extensions are a first-class attack surface.
2. Rotate Credentials That Were in the Vault During the Exposure Window
If your organization used the Passportal Chrome or Edge extension during the vulnerable period, assume exposure. Rotate:
- All credentials stored in the vault during that window
- Any service accounts or API keys that were accessible via the extension
- Admin credentials — especially those with access to your RMM, firewall, or identity provider
Prioritize by blast radius. What would hurt most if those credentials were already in an attacker's hands right now? Start there. Our guide to IT documentation breach incident response and password exposure walks through exactly how to triage this kind of rotation under pressure.
3. Reassess Your Password Manager's Architecture Before Trusting It Again
Not all password managers are built the same. The Passportal flaw was partly enabled by how the extension interacted with the browser's DOM and how decrypted data was handled in memory. Before you re-extend trust to any vault tool, ask:
- Does the extension decrypt credentials locally, or does it pass decrypted data to a cloud service?
- What permissions does the extension request, and are they the minimum necessary?
- Does the vendor have a published security architecture and a history of responsible disclosure?
- Is there a hardware-backed or app-based alternative that doesn't require a browser extension at all?
For MSPs managing multiple clients, this question is even more urgent — one compromised extension on one technician's browser can expose every client vault simultaneously.
The Broader Pattern You Can't Ignore
The Passportal flaw isn't an outlier. It's a data point in a clear trend: the tools that sit closest to your credentials — password managers, browser extensions, RMM agents, documentation platforms — are exactly what sophisticated attackers are targeting now. Supply chain risk isn't a concept from a conference talk. It's the N-Able extension. It's the Rust crates. It's the Entra ID exploit in active use today.
Small business IT admins are particularly exposed because they're often managing this alone, without a SOC watching for anomalies or a threat intel feed flagging suspicious vault access. The extension runs silently, the credentials leak silently, and the attacker moves silently — until they don't.
The only real defense is reducing the attack surface before the next flaw is discovered: fewer extensions, tighter permissions, credential rotation hygiene, and continuous visibility into what's exposed in your environment right now.
Take Action: Don't Wait for the Next Vault Leak
The Passportal vulnerability is a reminder that your biggest risks often live inside the tools you already trust. Proactive scanning catches misconfigurations, exposed services, and attack surface issues before an attacker does — not after.
Oscar Six Security's Radar gives small business IT admins and MSPs an affordable, no-fluff way to see what's actually exposed in their environment. At $99 per scan, it's built for the IT admin managing security without a full security team behind them.
Focus Forward. We've Got Your Six.