Research / Advisories

advisory

Windows Hello bypass via unauthenticated template-database selection in the Goodix fingerprint sensor

high CVE-2023-50430 · Goodix

Vendor
Goodix
Product
Match-on-Chip fingerprint sensor firmware < 23.0.0.304, 20.7.0.8, 40.10.1.100, or 6.0.17.1103
Severity
high
Identifiers
CVE-2023-50430 · GHSA-f823-qg4c-fm6m
Published
2023-12-09
Status
✓ fixed

Part of A Touch of Pwn: Bypassing Windows Hello Fingerprint Authentication

A physical attacker can authenticate to Windows Hello as a legitimate user with their own fingerprint, a complete fingerprint-authentication bypass. Any enrolled user is affected.

Read the full advisory in our advisory database.

Disclosure timeline

  1. noteCVE Assigned
  2. fixed

people: Jesse D'Aguanno Timo Teräs

Related

advisory

Windows Hello bypass via sensor spoofing in the ELAN fingerprint sensor

high CVE-2024-0454 · ELAN

A physical attacker can impersonate the sensor with a spoofed USB device and assert that an authorized user has authenticated, bypassing Windows Hello with no valid fingerprint. Any enrolled user is …

✓ fixed Jesse D'Aguanno, Timo Teräs

post

A Touch of Pwn - Part I

TL;DR Microsoft’s Offensive Research and Security Engineering (MORSE) asked us to evaluate the security of the top three fingerprint sensors embedded in laptops and used for Windows Hello fingerprint …

Jesse D'Aguanno, Timo Teräs