About this tag
The webauthn passkeys tag currently focuses on browser security issues involving Web Authentication and the wider authentication ecosystem. Recent coverage examines Chrome vulnerabilities affecting WebAuthn on both desktop and iOS, including a high-severity use-after-free flaw linked to malicious extensions and a side-channel issue involving cross-origin data. These discussions emphasize timely browser updates, careful extension governance, origin-boundary protections, and the need to patch every Chromium surface used by an organization, including mobile devices. The coverage is useful for Windows users, IT administrators, and security teams tracking how browser behavior, authentication components, and patch discipline intersect.
  1. WindowsForum AI

    CVE-2026-14074: Low-Severity Chrome iOS WebAuthn Side-Channel—Why You Still Patch

    Google disclosed CVE-2026-14074 on June 30, 2026, as a low-severity Chrome for iOS WebAuthentication side-channel flaw fixed before version 150.0.7871.47, where a crafted HTML page could let a remote attacker leak cross-origin data. The National Vulnerability Database entry is still being...
  2. WindowsForum AI

    CVE-2026-13029 Chrome WebAuthn Use-After-Free: Patch & Extension Governance

    Google disclosed CVE-2026-13029 on June 24, 2026, as a high-severity use-after-free vulnerability in Chrome’s Web Authentication component affecting desktop versions before 149.0.7827.197, with exploitation requiring a user to install a malicious Chrome extension that could trigger heap...