RootData Free Push Service: Submit exclusive financing info and upon approval, enjoy free App push notifications. [Contact Now]
API Download the RootData App

Slow Fog CISO: WebAuthn Key Login Has Significant Security Risks

Sep 22, 2025 15:22:48

Share to

ChainCatcher news, Slow Mist's information security officer 23pds posted on platform X about a new type of WebAuthn key login bypass attack method. Attackers can hijack the WebAuthn API through malicious browser extensions or website XSS vulnerabilities, forcing a downgrade to password login or tampering with the key registration process to steal credentials. This attack can be completed without physical access to the device or access to biometric features.

WebAuthn is an important web authentication standard established by W3C and the FIDO Alliance, supporting various authentication methods such as hardware keys and biometrics, and is currently widely used for secure website logins. It is recommended that relevant enterprises and users pay timely attention to this security risk.

Recent Fundraising

More
-- Sep 23
-- Sep 20
-- Aug 06

New Tokens

More
Sep 05
Sep 04
Sep 03

Latest Updates on 𝕏

More