SlowMist CISO: WebAuthn Key Login Has Major Security Risks
ChainCatcher news, SlowMist Chief Information Security Officer 23pds posted on X platform, stating that there is a new type of WebAuthn key login bypass attack. Attackers can hijack the WebAuthn API through malicious browser extensions or website XSS vulnerabilities, forcing a downgrade to password login or tampering with the key registration process to steal credentials. This attack can be carried out without physical access to the device or access to biometric features.
WebAuthn is an important web authentication standard developed by W3C and the FIDO Alliance, supporting multiple authentication methods such as hardware keys and biometrics, and is currently widely used for secure website logins. Relevant enterprises and users are advised to pay close attention to this security risk in a timely manner.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Canadian Dollar remains subdued near two-month lows as falling oil prices weigh
Jamie Dimon Says the Dollar Only Stays Dominant if the US Makes Trade Deals

Wall Street Tokenization Explained: Will Blockchain Replace Today's Stock Trading Stack?

British Pound seems vulnerable near two-month low as USD bulls eye US PCE and GDP
