Security

CSO

Google apologizes for breaking password manager for millions of Windows users with iffy Chrome update

Happy Sysadmin Day


Google celebrated Sysadmin Day last week by apologizing for breaking its password manager for millions of Windows users – just as many Windows admins were still hard at work mitigating the impact of the faulty CrowdStrike update.

The Google glitch occurred late last week and took until July 25 for the nearly 18-hour incident to finally be signed off as fixed.

The issue, which was limited to Windows users on the M127 version of the Chrome browser, meant that users were unable to find saved passwords. "Approximately 2 percent of users out of the 25 percent of the entire user base where the configuration change was rolled out, experienced this issue," Google said.

According to the search giant, "the root cause of the issue is a change in product behavior without proper feature guard." It all sounds suspiciously like a faulty update being pushed out.

The issue was global, and the actual number of affected users could run into the millions. According to figures from the International Telecommunication Union (ITU), there were 5.4 billion internet users in 2023. Chrome's market share is 65.68 percent, according to StatCounter. As such, more than 17 million users might have received the broken update and, as Google put it, "experienced the issue."

Google Password Manager works by storing a user's credentials in their Google Account. It will also suggest strong and unique passwords "so you don't have to remember them," according to the ad slinger.

That's assuming, of course, the service doesn't abruptly disappear for almost a day because Google pushed out a broken update.

The incident highlights the risks of using a browser-based password manager, even from a vendor the size of Google, where a broken browser update could leave the password stash inaccessible. Password managers are, however, an increasingly important facet of modern life. Popular ones include LastPass, which suffered a serious breach in 2022, or Bitwarden.

Using a password manager is a sensible precaution from a security perspective. However, while letting your browser take care of things might be convenient, it also carries its own risks. ®

Send us news
13 Comments

Google's 10-year Chromebook lifeline leaves old laptops headed for silicon cemetery

Longer support for newer models won't save prior versions from scrapheap

Brit watchdog probes Google's search, ads empire

Third front opened amid continued scrutiny from US, Euro regulators

Tired of begging, Microsoft now trying to trick users into thinking Bing is Google

If you can't beat 'em, just imitate their branding, hide yours and hope they don't notice

Google and Linux Foundation form Chromium love club

Right as Uncle Sam pushes for Chrome sell-off, eh?

Google reports halving code migration time with AI help

Chocolate Factory slurps own dogfood, sheds drudgery in specific areas

Fortinet: FortiGate config leaks are genuine but misleading

Competition hots up with Ivanti over who can have the worst start to a year

Is it really the plan to take over Greenland and the Panama Canal? It's been a weird week

Meanwhile, tech titans are falling over themselves to help Trump

Honey co-founder's Pie Adblock called out for copying GPL'd uBlock Origin files

And, magically, a repo appears on GitHub with attribution

RISC-V is making moves, but it has work to do if it wants to hit the mainstream

Can it topple x86 and Arm, or is the gap too wide to close?

Guide for the perplexed – Google is no longer the best search engine

Seek and ye shall find

Why Google's Chrome monopoly won't crack anytime soon

Haven't we heard this story before?

Microsoft won't let customers opt out of passkey push

Enrollment invitations will continue until security improves