Breaking the Passkey Promise: SquareX Discloses Major Passkey Vulnerability at DEF CON 33
ID: 5533377a-315c-5bf2-8a2d-4d55361b3518
STIX ID: report--5533377a-315c-5bf2-8a2d-4d55361b3518
Feed Name: Security Ledger
Threat Score
SquareX disclosed a passkey vulnerability at DEF CON showing that relatively simple malicious browser scripts and extensions can intercept and fake passkey registration and authentication flows, allowing attackers to access accounts (including banking and enterprise SaaS) without the user's device or biometrics; the report warns that EDR and network controls lack visibility into browser-native attacks and urges adoption of Browser Detection and Response (BDR).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
