Security researchers were able to bypass authentication on three popular laptops by testing the fingerprint sensors used for Windows Hello. The research was done by Blackwing Intelligence and Microsoft’s MORSE.
Target devices include a Dell Inspiron 15 with a Goodix fingerprint sensor, a Lenovo ThinkPad T14s with a Synaptics sensor, and a Microsoft Surface Pro X with an ELAN sensor. The embedded fingerprint sensors and the host were targeted with software and hardware attacks.
By infosecbulletin
/ Wednesday , September 2 2026
SonicWall unveiled advisory SNWLID-2026-0016 on September 1, 2026. It states that two SMA1000 flaws are being actively exploited. The main...
Read More
By infosecbulletin
/ Wednesday , September 2 2026
The market for AI SOC agents is early, crowded, and full of claims that haven't been tested in production. This Gartner...
Read More
By infosecbulletin
/ Tuesday , September 1 2026
Almost 22,000 Microsoft Exchange servers are online and still vulnerable to a flaw that lets attackers access all user mailboxes. Tracked...
Read More
By infosecbulletin
/ Monday , August 31 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed two flaws in PaperCut NG and PaperCut MF in its...
Read More
By infosecbulletin
/ Monday , August 31 2026
The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco...
Read More
By infosecbulletin
/ Sunday , August 30 2026
Many serious security flaws have been found in WordPress plugins and themes, such as WPMU DEV Dashboard, Avada, TranslatePress, Pods,...
Read More
By infosecbulletin
/ Saturday , August 29 2026
700 AI agents supposedly escaped their isolation, created a secret communication channel, and worked together to attack Hugging Face's systems....
Read More
By infosecbulletin
/ Friday , August 28 2026
ServiceNow issued security updates for three new serious AI Platform problems that can be used in code injection, SQL injection,...
Read More
By infosecbulletin
/ Friday , August 28 2026
Over 100 tech, cybersecurity, and finance groups have signed an open letter with OpenAI. They want a global increase in...
Read More
By infosecbulletin
/ Friday , August 28 2026
3 airports in the UK were affected by a "cyber security incident." Hackers got into data belonging to nearly nine...
Read More
AlSO READ:
By 2025, Domestic cloud market expected $46.3 million; MD “DataHub Asia”
The sensors that were tested are Match-on-Chip, meaning the chip has a microprocessor and memory, and the fingerprint data always stays within the sensor. To bypass authentication, one would need to physically attack the chip itself.
To carry out the attack, the attacker needs to physically get hold of the device. This means they would have to either steal the device or use the evil maid method.
The researchers showed how to carry out attacks by connecting a hacking device to a laptop using USB or by connecting a specially crafted rig to the fingerprint sensor.
For Dell and Lenovo laptops, the Windows Hello fingerprint authentication was bypassed by manipulating valid user fingerprint ID numbers and enrolling the attacker’s fingerprint by imitating a legitimate user’s ID.
To hack the Surface device, the attacker must disconnect the Type Cover, which is the keyboard and fingerprint sensor, and connect a USB device that tricks the fingerprint sensor into thinking it’s an authorized user logging in.
Blackwing published a blog post on Tuesday about their findings. Microsoft also released a video of the Blackwing researchers presenting their findings at the BlueHat conference in October.