Identity & Access

Passkey Login Bypassed via WebAuthn Process Manipulation

Researchers at enterprise browser security firm SquareX showed how an attacker can impersonate a user and bypass passkey security. 

Passkey bypass

Researchers at enterprise browser security firm SquareX have demonstrated an attack method that can be used to gain access to an account protected by passkeys.

Passkeys are designed to provide a more secure alternative to passwords, enabling users to log into their account based on a private key stored on the device. Users can sign in using various authentication methods, including PIN, facial recognition, or fingerprint scan. 

Passkeys are increasingly adopted and recommended by major tech companies such as Microsoft, Amazon, and Google.

Unlike passwords, passkeys are considered phishing resistant as a fake website cannot trick users into handing over their passkey. 

However, researchers at SquareX showed at DEF CON over the weekend that under certain circumstances passkeys can be bypassed. It’s worth pointing out that the attack does not target passkey cryptography, but rather it shows the potential for a compromised browser environment to manipulate the process that passkeys rely on.

The attack they described involves the attacker impersonating the targeted user and bypassing passkey-based login security, even in scenarios where Face ID is used and the hacker does not have access to the actual device.

Advertisement. Scroll to continue reading.

The attack targets WebAuthn, the standard that provides a way for users to authenticate to websites and applications through passkeys. 

“When registering or authenticating on websites using passkeys, the website communicates via the browser by calling the WebAuthn APIs. In this attack, the attacker forges both the registration and login flows by hijacking the WebAuthn API through JavaScript injection,” Shourya Pratap Singh, principal software engineer at SquareX, told SecurityWeek

In order to conduct an attack, a threat actor needs to convince the targeted user to install a malicious browser extension. The attacker can, for instance, disguise the malicious extension as a useful tool and upload it to an extension repository.  

Alternatively, a client-side vulnerability on the targeted website, such as an XSS bug that allows JavaScript injection, can be exploited to carry out an attack.

The attack involves hijacking and manipulating the passkey registration and authentication processes. If the user has already registered on the targeted website, the attacker can reinitiate the passkey registration process, or they can force the victim to downgrade to password-based authentication and then obtain the credentials.

“For victims, it is enough to visit the website where they log in using passkeys with the malicious extension installed, or simply visit the website directly if it contains a client-side injection vulnerability (e.g., via XSS),” Singh explained. “No additional user interaction is required beyond normal registration and authentication.”

Related: Browser Extensions Pose Serious Threat to Gen-AI Tools Handling Sensitive Data

Related: Passkey News: FIDO Unveils New Specifications, Amazon Announces 175 Million Users

Related: Google Now Syncing Passkeys Across Desktop, Android Devices

Related Content

Identity & Access

Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.

Malware & Threats

Published through five accounts, the extensions appear part of a coordinated campaign based on shared C&C infrastructure.

Artificial Intelligence

Malicious extensions could hijack the Gemini Live in Chrome feature to spy on users and steal their files.

Artificial Intelligence

Marketed as ChatGPT enhancement and productivity tools, the extensions allow the threat actor to access the victim's ChatGPT data.

Malware & Threats

Impersonating a legitimate extension from AITOPIA, the two malicious extensions were also exfiltrating users’ browser activity.

Malware & Threats

The extensions were seen profiling users, reading cookie data to create unique identifiers, and executing payloads with browser API access.

Data Protection

All new extensions will be required to declare their data collection practices in their manifest file using a specific key.

Endpoint Security

ReVault vulnerabilities in the ControlVault3 firmware in Dell laptops could lead to firmware modifications or Windows login bypass.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version