Czech Republic based security researcher Marek Tóth, unveiled a series of unpatched zero-day clickjacking security vulnerabilities impacting the browser-based plugins for a wide range of password managers:
https://marektoth.com/blog/dom-based-extension-clickjacking/
Is this now fixed in all Enpass Browser Extensions?
This is only mentioned in the release notes for the Chrome Extension (6.11.6):
„Fixed a clickjacking vulnerability in the extension by preventing popover windows from overlaying the inline menu (Reported by Marek Tóth)“