AutoSpill attack steals credentials from Android password managers

"In an attack scenario, a rogue app serving a login form could capture the userโ€™s credentials without leaving any indication of the compromise."

https://www.bleepingcomputer.com/news/security/autospill-attack-steals-credentials-from-android-password-managers/

Reply to this note

Please Login to reply.

Discussion

So this is basically the same as the known autofill issues but the attack is served from a malicious app?

So disable autofill is still best practice mitigation.

So just copy n paste?