Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
Security-relevant changes and known issues, newest first. We list weaknesses here as well as fixes. To report a problem, see the disclosure policy.
A copied 2FA code is cleared after 30 seconds only while the app stays open, and is not marked sensitive. The website previously said copied codes are always cleared. Fix planned for the next version; no date set.
Clipboard and screenshot protectionsRemoved our custom Bluetooth Pair via QR flow from the Passkey tab. A standard passkey QR code scanned with the phone camera is handled by Android, which may use the internet and Bluetooth for it. The privacy policy and security page now say so.
Why we dropped our custom Bluetooth passkey protocolThe provider now refuses to create a duplicate passkey when the site lists one we already hold (InvalidStateError), offers only the credentials a site allows at sign-in, fails with NotSupportedError when ES256 is not offered, and returns attestation format none with a zeroed authenticator ID unless the site asks for attestation. Checked on webauthn.io and GitHub.
WebAuthn correctness checklistAutofill matched web pages by a simplified service name that ignored the ending, so a password saved for github.com could have been offered, after the biometric check, on github.xyz. Web pages now need the exact registered domain. Found in our own review before the first release, so no released version was affected.
How Autofill and Vault protect each fill