Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnAISquareMore
SlowMist CISO: WebAuthn Key Login Has Major Security Risks

SlowMist CISO: WebAuthn Key Login Has Major Security Risks

ChaincatcherChaincatcher2025/09/22 07:39
Show original

ChainCatcher news, SlowMist Chief Information Security Officer 23pds posted on X platform, stating that there is a new type of WebAuthn key login bypass attack. Attackers can hijack the WebAuthn API through malicious browser extensions or website XSS vulnerabilities, forcing a downgrade to password login or tampering with the key registration process to steal credentials. This attack can be carried out without physical access to the device or access to biometric features.

WebAuthn is an important web authentication standard developed by W3C and the FIDO Alliance, supporting multiple authentication methods such as hardware keys and biometrics, and is currently widely used for secure website logins. Relevant enterprises and users are advised to pay close attention to this security risk in a timely manner.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!