xss

Tag

Cards List
#xss

XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None

Lobsters Hottest · 2026-05-20 Cached

The article explains how a single XSS vulnerability can defeat the phishing-resistance of passkeys when attestation is set to 'none', allowing attackers to register their own passkeys and achieve persistent account takeover. It calls for attention to this overlooked threat and suggests defenses.

0 favorites 0 likes
← Back to home

Submit Feedback