ChainCatcher news, Slow Mist's information security officer 23pds posted on platform X indicating a new type of WebAuthn Secret Key log in bypass attack method. Attackers can hijack the WebAuthn API through malicious browser extensions or website XSS vulnerabilities, forcing a downgrade to password log in or tampering with the Secret Key registration process to steal credentials. This attack can be completed without physical contact with the device or access to biometric functions. WebAuthn is an important Web authentication standard developed by W3C and the FIDO Alliance, supporting various authentication methods such as hardware keys and biometrics, and is currently widely used for website secure log in. Relevant enterprises and users are advised to follow this security risk promptly.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Slow Fog CISO: There are significant security risks associated with WebAuthn Secret Key log in.
ChainCatcher news, Slow Mist's information security officer 23pds posted on platform X indicating a new type of WebAuthn Secret Key log in bypass attack method. Attackers can hijack the WebAuthn API through malicious browser extensions or website XSS vulnerabilities, forcing a downgrade to password log in or tampering with the Secret Key registration process to steal credentials. This attack can be completed without physical contact with the device or access to biometric functions. WebAuthn is an important Web authentication standard developed by W3C and the FIDO Alliance, supporting various authentication methods such as hardware keys and biometrics, and is currently widely used for website secure log in. Relevant enterprises and users are advised to follow this security risk promptly.