[Bug]: Reset password functionality allows reuse of existing password #33435
Labels
feature-branch-bug
bug that was found on a feature branch, but not yet merged in main branch
needs-triage
Issue needs to be triaged
seedless-onboarding
Any issues related to the seedless onboarding feature
Sev1-high
High severity; partial loss of service with severe impact upon users, with no workaround.
type-bug
Something isn't working
Uh oh!
There was an error while loading. Please reload this page.
Describe the bug
The reset password feature permits users to set their current password as the new password during the reset process. This behavior undermines the purpose of a password reset, which is to enforce the creation of a new, secure password. Allowing the reuse of the existing password poses a potential security risk and does not align with standard password reset practices.
Expected behavior
Related PR - #33385
Screenshots/Recordings
Screen.Recording.2025-06-02.at.9.02.00.PM.mov
Steps to reproduce
#test007
) as the "New Password"(#test007
) during the reset process.Error messages or log output
Detection stage
On a feature branch
Version
12.18.1
Build type
None
Browser
Chrome
Operating system
Windows, MacOS
Hardware wallet
No response
Additional context
No response
Severity
No response
The text was updated successfully, but these errors were encountered: