Security

CSO

Google apologizes for breaking password manager for millions of Windows users with iffy Chrome update

Happy Sysadmin Day


Google celebrated Sysadmin Day last week by apologizing for breaking its password manager for millions of Windows users – just as many Windows admins were still hard at work mitigating the impact of the faulty CrowdStrike update.

The Google glitch occurred late last week and took until July 25 for the nearly 18-hour incident to finally be signed off as fixed.

The issue, which was limited to Windows users on the M127 version of the Chrome browser, meant that users were unable to find saved passwords. "Approximately 2 percent of users out of the 25 percent of the entire user base where the configuration change was rolled out, experienced this issue," Google said.

According to the search giant, "the root cause of the issue is a change in product behavior without proper feature guard." It all sounds suspiciously like a faulty update being pushed out.

The issue was global, and the actual number of affected users could run into the millions. According to figures from the International Telecommunication Union (ITU), there were 5.4 billion internet users in 2023. Chrome's market share is 65.68 percent, according to StatCounter. As such, more than 17 million users might have received the broken update and, as Google put it, "experienced the issue."

Google Password Manager works by storing a user's credentials in their Google Account. It will also suggest strong and unique passwords "so you don't have to remember them," according to the ad slinger.

That's assuming, of course, the service doesn't abruptly disappear for almost a day because Google pushed out a broken update.

The incident highlights the risks of using a browser-based password manager, even from a vendor the size of Google, where a broken browser update could leave the password stash inaccessible. Password managers are, however, an increasingly important facet of modern life. Popular ones include LastPass, which suffered a serious breach in 2022, or Bitwarden.

Using a password manager is a sensible precaution from a security perspective. However, while letting your browser take care of things might be convenient, it also carries its own risks. ®

Send us news
13 Comments

Rock Chrome hard enough and get paid half a million

Google revises Chrome Vulnerability Rewards Program with higher payouts for bug hunters

Yelp accuses Google of being a local search bully in antitrust lawsuit

Chocolate Factory claims rival is trying to revive cases it's already lost

Chrome dumped support for Ubuntu 18.04 – but it'll be back

Complaints about lack of notice plus an inquiry from El Reg prompt U-turn by web giant

Deadline looms: Google Workspace mandates OAuth by September 30

27 days to get your users' third-party apps on Google’s sign-in

Google’s Irish bit barn plans denied over eco shortfall

DCs on the Emerald Isle better be green, says Dublin council - unless your name is Microsoft

The future of AI/ML depends on the reality of today – and it's not pretty

The return of Windows Recall is more than a bad flashback

Google is a monopoly. The fix isn't obvious

A business breakup may be coming – but what comes after may not be better

What is missing from the web? We're asking for Google

Besides sanity, of course

Google trains a GenAI model to simulate Doom's game engine in real-ish time

The proof of concept shows promise despite big limitations

Digital wallets can allow purchases with stolen credit cards

Researchers find it's possible to downgrade authentication checks, and shabby token refresh policies

Chrome Web Store warns end is nigh for uBlock Origin

Will you see the Lite?

Google raps Iran's APT42 for raining down spear-phishing attacks

US politicians and Israeli officials among the top targets for the IRGC’s cyber unit