Proton Pass fixed the autofill problem — including the one inside iframes
Proton says an upgrade to how Pass detects login forms clears 80% of the autofill issues users had reported, including forms inside iframes that banks and shopping sites rely on. Plus 2FA codes that copy themselves, and an installer IT teams can actually deploy.

Table of contents
Password managers live or die on one thing, and it isn't encryption. It's whether the thing fills in your password when you need it to. Proton has shipped an update to Pass that goes after exactly that, and the most interesting part of it is a case most people never think about: login forms inside iframes.
Autofill now reaches forms it previously couldn't
The change is to how Pass detects login forms in the first place. The headline claim from Proton is that the upgrade resolves 80% of the autofill issues users had reported.
The specific gap worth calling out is forms loaded inside iframes — a page embedding a separate document inside itself. Plenty of banks, shopping platforms and social networks build their login this way, often because the authentication is handled by a different system than the page you're looking at. If your password manager doesn't handle that case, it silently does nothing on exactly the sites where you least want to be typing a password by hand.
Two honest caveats on that 80%. It is Proton's own figure, drawn from issues users reported to them rather than an independent measurement — the real-world number depends entirely on which sites you use. And "reported issues" is a narrower set than "all failures": the ones that never got reported aren't in the denominator.
Iframes are the part worth understanding
This is where a bit of context helps, because "autofill in iframes" sounds like a pure win and isn't quite that simple.
Password managers have historically been cautious about filling credentials into embedded frames, and for a good reason: an iframe can load content from a different origin than the page around it. A manager that fills a password into any frame that asks is a manager that can be tricked into handing credentials to a frame the attacker controls, sitting invisibly inside an otherwise legitimate page.
The sane implementation restricts filling to frames whose origin matches what the credential is stored against, rather than trusting the parent page. Proton's announcement describes the improvement in terms of detection rather than spelling out the origin rules, so we can't verify from it alone exactly where their line sits — that's a fair question to ask of any manager shipping this, not a criticism specific to Pass.
2FA codes can now copy themselves
The second change is smaller and, day to day, probably the one you'll notice more. Pass can now be set to automatically copy your 2FA code to the clipboard.
The point is what happens when autofill doesn't appear. Instead of switching apps, finding the entry and reading six digits off a screen before they expire, the code is already sitting in your clipboard ready to paste. It removes the most common moment of friction in an otherwise smooth login.
Worth knowing: anything on your clipboard is readable by other apps on most platforms, and clipboard history tools will happily keep it. For a code that expires in thirty seconds that's a modest exposure, but it isn't zero.
For IT: the Windows installer moved to .msix
The change with the least consumer relevance and the most business relevance: the Windows installer is now .msix, which works natively with Microsoft Intune.
In practice that means an admin can push Pass to every company device centrally rather than walking through machines one at a time. If you have ever been the person responsible for getting a password manager onto fifty laptops, you already know why that line matters more than it reads.
Why this is a security story, not a convenience one
It's tempting to file autofill under user experience. It isn't.
When autofill fails, people don't carefully retrieve the password from the vault and type it. They fall back to the password they can remember — which is the one they've used elsewhere. Every failed autofill is a small nudge toward reuse, and password reuse is the mechanism behind the majority of account takeovers that follow a breach. Friction in a password manager doesn't just annoy people; it quietly pushes them back to the behaviour the manager exists to prevent.
That's the honest reason a reliability update deserves attention while a new feature might not. We've made the same argument in can a VPN protect you from password leaks — the tools only help if the habits survive contact with daily use.
If you're weighing up which of these tools you actually need, VPNs vs firewalls vs password managers sets out what each one does and doesn't cover.
Bottom line
This is a maintenance release rather than a headline feature, and that's the point — it fixes the thing most likely to make someone give up on a password manager altogether. If you tried Pass previously and abandoned it because it didn't fill reliably on the sites you use, this is the update that makes it worth a second look.
If you're already settled elsewhere and autofill works, there's nothing here that demands you move.
Sources


