Password managers can be tricked into believing that malicious Android apps are legitimate
https://www.zdnet.com/article/password-managers-can-be-tricked-into-believing-that-malicious-android-apps-are-legitimate/

Password managers from Keeper, Dashlane, LastPass, and 1Password found to be vulnerable, study finds.