κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / Passkey Login Bypassed via WebAuthn Process Manipulation
άμυνα
.

Passkey Login Bypassed via WebAuthn Process Manipulation

14/08/2025

Researchers at enterprise browser security firm SquareX have demonstrated an attack method that can be used to gain access to an account protected by passkeys.

Passkeys are designed to provide a more secure alternative to passwords, enabling users to log into their account based on a private key stored on the device. Users can sign in using various authentication methods, including PIN, facial recognition, or fingerprint scan. 

Passkeys are increasingly adopted and recommended by major tech companies such as Microsoft, Amazon, and Google.

Unlike passwords, passkeys are considered phishing resistant as a fake website cannot trick users into handing over their passkey. 

However, researchers at SquareX showed at DEF CON over the weekend that under certain circumstances passkeys can be bypassed. It’s worth pointing out that the attack does not target passkey cryptography, but rather it shows the potential for a compromised browser environment to manipulate the process that passkeys rely on.

The attack they described involves the attacker impersonating the targeted user and bypassing passkey-based login security, even in scenarios where Face ID is used and the hacker does not have access to the actual device.

The attack targets WebAuthn, the standard that provides a way for users to authenticate to websites and applications through passkeys. 

“When registering or authenticating on websites using passkeys, the website communicates via the browser by calling the WebAuthn APIs. In this attack, the attacker forges both the registration and login flows by hijacking the WebAuthn API through JavaScript injection,” Shourya Pratap Singh, principal software engineer at SquareX, told SecurityWeek. 

In order to conduct an attack, a threat actor needs to convince the targeted user to install a malicious browser extension. The attacker can, for instance, disguise the malicious extension as a useful tool and upload it to an extension repository.  

Alternatively, a client-side vulnerability on the targeted website, such as an XSS bug that allows JavaScript injection, can be exploited to carry out an attack.

The attack involves hijacking and manipulating the passkey registration and authentication processes. If the user has already registered on the targeted website, the attacker can reinitiate the passkey registration process, or they can force the victim to downgrade to password-based authentication and then obtain the credentials.

“For victims, it is enough to visit the website where they log in using passkeys with the malicious extension installed, or simply visit the website directly if it contains a client-side injection vulnerability (e.g., via XSS),” Singh explained. “No additional user interaction is required beyond normal registration and authentication.”

Related: Browser Extensions Pose Serious Threat to Gen-AI Tools Handling Sensitive Data

Related: Passkey News: FIDO Unveils New Specifications, Amazon Announces 175 Million Users

Related: Google Now Syncing Passkeys Across Desktop, Android Devices

Source: securityweek.com

Filed Under: INDUSTRY NEWS Tagged With: Source-8

Haiku and SerenityOS aren’t daily drivers, but they’re the best weekend projects

Most people stick to Windows, macOS, or Linux because they get the job done with minimal hassle. They support a vast range of hardware, have robust ecosystems, and are built for day-to-day use. That doesn’t mean they’re the only operating systems worth trying. Away from the mainstream, projects like Haiku and SerenityOS demonstrate that there’s still plenty of room for alternative visions of how … [Read More...]

I clustered budget-friendly devices into a Proxmox HA lab, and it's more useful than I thought

Between its support for LXCs, community scripts, and simple management UI, Proxmox has a ton of features to make home labs more accessible to beginners and casual users. Unlike its rivals (especially ESXi), Proxmox requires minimal CPU, memory, and storage provisions. It also works right-out-of-the-box with most hardware, making it a terrific option for budget-friendly setups. However, despite its … [Read More...]

If you just need a laptop for the basics, this one at $349 is an absolute steal

This laptop is perfect for someone that's looking for something new on a budget. The Asus Vivobook 15 packs power with an Intel Core 5 processor, and also comes with a good amount of RAM and storage. But what makes it stand out right now is that steep discount from Walmart. For a limited time, you can score this laptop for $349, which is an absolute steal. Source: xda-developers.com … [Read More...]

The best Prime Day SSD deals: Save on gear from Samsung, Crucial, Seagate and others

If you've never considered adding a solid-state drive (SSD) to your PC or game console, October Prime Day is a great time to start — and if you already know what a difference extra storage can make, October Prime Day is the perfect time to outfit your build. For those who haven't heard of SSDs, they're physical upgrades that stack on top of a device's storage to make more files accessible at once. … [Read More...]

3 mistakes that ruined my first attempt at building a PC

Building your very first PC is never really easy, no matter how many tutorials you've watched on YouTube or parts you've memorized. In fact, it took me a couple of weeks just to properly research and source the parts for my first gaming rig back in 2012. By the time everything arrived, I thought the hard part was behind me. I knew that putting the parts together as a beginner would be … [Read More...]

The Reinforcement Gap — or why some AI skills improve faster than others  

AI coding tools are getting better fast. If you don’t work in code, it can be hard to notice how much things are changing, but GPT-5 and Gemini 2.5 have made a whole new set of developer tricks possible to automate, and last week Sonnet 2.4 did it again.   At the same time, other skills are progressing more slowly. If you are using AI to write emails, you’re probably getting the same … [Read More...]

The best Amazon Prime Day kitchen deals: Get up to 50 percent off our favorite air fryers and more

Whether you call it October Prime Day or use Amazon’s official title, Prime Big Deal days, the sale represents some of the lowest prices of the year in nearly every department — and that includes kitchen gear. We have a slew of food enthusiasts on staff who have tested plenty of excellent kitchen tech, as seen in our reviews and buying guides. We’ve covered everything from air fryers to sous vide … [Read More...]

Astronomers Spot Rapidly Growing Rogue Planet Feeding on Surrounding Gas

Astronomers have identified the fastest-growing planet ever observed, a free-floating world known as Cha 1107-7626. Located about 620 light-years from Earth, it is between five and ten times the mass of Jupiter. The rogue planet has been detected, and it has entered a sudden growth burst in recent months. It is swallowing down six billion tonnes of gas every second, making it the hungriest … [Read More...]

4 reasons why installing HACS was the best decision for my Home Assistant instance

While the Home Assistant Community Store (HACS) is considered by some people to be one of the best tools you can use with Home Assistant, I only stumbled upon it a while after setting up my own server. I'm still very early in my Home Assistant journey, but as I've gotten to know the platform better, I've realized that installing HACS was the best decision for my instance. Source: … [Read More...]

The Young Minds App wants to protect and educate children online and will show its tech at TechCrunch Disrupt 2025

An app called Young Minds wants to give parents control over what their kids do on the internet, while also protecting their children’s privacy and teaching them good online habits.  The startup was founded by Nino Dvalidze (pictured), an entrepreneur and a mother of two from the United Kingdom. Dvalidze told TechCrunch that the idea for Young Minds came from conversations with fellow … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • Haiku and SerenityOS aren’t daily drivers, but they’re the best weekend projects
  • I clustered budget-friendly devices into a Proxmox HA lab, and it's more useful than I thought
  • If you just need a laptop for the basics, this one at $349 is an absolute steal
  • The best Prime Day SSD deals: Save on gear from Samsung, Crucial, Seagate and others
  • 3 mistakes that ruined my first attempt at building a PC

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023