Security

CSO

Google apologizes for breaking password manager for millions of Windows users with iffy Chrome update

Happy Sysadmin Day


Google celebrated Sysadmin Day last week by apologizing for breaking its password manager for millions of Windows users – just as many Windows admins were still hard at work mitigating the impact of the faulty CrowdStrike update.

The Google glitch occurred late last week and took until July 25 for the nearly 18-hour incident to finally be signed off as fixed.

The issue, which was limited to Windows users on the M127 version of the Chrome browser, meant that users were unable to find saved passwords. "Approximately 2 percent of users out of the 25 percent of the entire user base where the configuration change was rolled out, experienced this issue," Google said.

According to the search giant, "the root cause of the issue is a change in product behavior without proper feature guard." It all sounds suspiciously like a faulty update being pushed out.

The issue was global, and the actual number of affected users could run into the millions. According to figures from the International Telecommunication Union (ITU), there were 5.4 billion internet users in 2023. Chrome's market share is 65.68 percent, according to StatCounter. As such, more than 17 million users might have received the broken update and, as Google put it, "experienced the issue."

Google Password Manager works by storing a user's credentials in their Google Account. It will also suggest strong and unique passwords "so you don't have to remember them," according to the ad slinger.

That's assuming, of course, the service doesn't abruptly disappear for almost a day because Google pushed out a broken update.

The incident highlights the risks of using a browser-based password manager, even from a vendor the size of Google, where a broken browser update could leave the password stash inaccessible. Password managers are, however, an increasingly important facet of modern life. Popular ones include LastPass, which suffered a serious breach in 2022, or Bitwarden.

Using a password manager is a sensible precaution from a security perspective. However, while letting your browser take care of things might be convenient, it also carries its own risks. ®

Send us news
13 Comments

Uncle Sam may force Google to sell Chrome browser, or Android OS

Tech giant snaps back, calls DoJ proposals on splitting up Alphabet and more 'government overreach'

Google Cloud burst by 12-hour power outage in German region

Loose juice led to cooling issue in one zone, but the pain was widespread

Alphabet posts big revenue and profit growth, just 1,100 job losses

Google Cloud grows fast thanks to AI, which now writes a quarter of all G-code

Russian court fines Google $20,000,000,000,000,000,000,000,000,000,000,000

Don't hold your breath Putin

Big browsers are about to throw a wrench in your ad-free paradise

Mozilla and Google complicate life for users of uBlock Origin and uBlock Lite

Google reportedly developing an AI agent that can control your browser

Project Jarvis will apparently conduct research, purchase products, and even book a flight on your behalf

Samsung phone users under attack, Google warns

Don't ignore this nasty zero day exploit says TAG

Tech giants set to pay through the nose for nuclear power that's still years away

Google, Amazon, Microsoft dive into costly deals that aren't generating anything yet

US Army should ditch tanks for AI drones, says Eric Schmidt

And what do you know, Google's former CEO just so happens to have a commercial solution

US lawmakers push DoJ to prosecute tax prep firms for leaking taxpayer data to big tech

TaxSlayer, H&R Block, TaxAct, and Ramsey Solutions accused of sharing info with Meta and Google

Bitwarden's FOSS halo slips as new SDK requirement locks down freedoms

Arguments continue but change suggests it's not Free Software anymore

Google's memory safety plan includes rehab for unsafe languages

Large C and C++ codebases will be around for the 'foreseeable future'