advisory
Windows Hello bypass via unauthenticated template-database selection in the Goodix fingerprint sensor
- Vendor
- Goodix
- Product
- Match-on-Chip fingerprint sensor firmware < 23.0.0.304, 20.7.0.8, 40.10.1.100, or 6.0.17.1103
- Severity
- high
- Identifiers
- CVE-2023-50430 · GHSA-f823-qg4c-fm6m
- Published
- 2023-12-09
- Status
- ✓ fixed
Part of A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication
A physical attacker can authenticate to Windows Hello as a legitimate user with their own fingerprint, a complete fingerprint-authentication bypass. Any enrolled user is affected.
Read the full advisory in our advisory database.
Disclosure timeline
- noteCVE Assigned
- fixed
people: Jesse D'Aguanno Timo Teräs
