Session Replication Attack Through QR Code Sniffing in Passkey CTAP Registration
摘要
Passkey is an authentication method to supplement passwords and leverages the open standard fast identity online (FIDO) and public key cryptography technology to ensure security. In this study, we uncover vulnerabilities within the Passkey registration process by employing the FIDO client to authenticator protocol (CTAP) method using a PC and an authenticator. We emphasize the risks of unauthorized individuals exploiting vulnerabilities in Chromium-based browsers to initiate concurrent registration processes, register their own Passkeys instead of legitimate users’, and the lack of registration success acknowledgment from the server to the authenticator. Considering these vulnerabilities, we implement a session replication attack, which is a local attack, through QR code sniffing during Passkey CTAP registration, and employed physical proximity and Wi-Fi jamming attacks within the Passkey registration process. We elucidate methods that enable these attacks and categorize the attack scenarios based on the smartphone of the victim. Our experimental results indicate a notable success rate for attackers, exceeding 87% for victims with Android phones and more than 67% success for victims with iPhones. We disclosed the vulnerabilities identified in Chromium-based browsers to Google.