According to the wiki, a one-click exfiltration vulnerability has existed for more than half a year and hasn't been fixed:
> In their default configurations, these extensions were shown to be exposed to a DOM-based extension clickjacking technique, allowing attackers to exfiltrate user data with just a single click. LastPass version 4.146.8 (September 12, 2025), which was intended to address the issue, remains vulnerable