SlowMist CISO: WebAuthn key login has bypass risks

PANews reported on September 22nd that SlowMist Technology's Chief Information Security Officer, 23pds, posted on the X platform that researchers have discovered a new attack that can bypass WebAuthn key-based login. Attackers can hijack the WebAuthn API through malicious browser extensions or exploit XSS vulnerabilities on websites, forcing downgrades to password login or tampering with the key registration process to steal user credentials. This attack does not require device access or Face ID. Victims who use key login on websites with malicious extensions or vulnerabilities may experience identity impersonation, leading to account compromise.

WebAuthn (Web Authentication) is a web standard developed by the W3C and FIDO Alliance. It aims to achieve secure authentication through public key cryptography, replacing or supplementing traditional passwords. Users can log in using hardware security keys (such as YubiKey), built-in platform authenticators (such as Windows Hello, Touch ID, Android biometrics), or devices that comply with the FIDO2 standard.

Share to:

Author: PA一线

This content is for informational purposes only and does not constitute investment advice.

Follow PANews official accounts, navigate bull and bear markets together
Recommended Reading
3 hour ago
8 hour ago
13 hour ago
14 hour ago
16 hour ago
2025-12-09 15:32

Popular Articles

Industry News
Market Trends
Curated Readings

Curated Series

App内阅读