AES CBC not broken, but it's likely LastPass implementation of AES was bad , such as bad RNG or other possible problems.
> such as bad RNG
How could that be a problem? The attacker doesn't control your passwords. How would you exploit a known IV as an attacker in this context?