Security researchers have detected a vulnerability in YubiKey two-factor authentication tokens that enables attackers to clone the device according to a new security advisory. The vulnerability was discovered within the Infineon cryptographic library used by most YubiKey products, including the YubiKey 5, Yubikey Bio, Security Key, and YubiHSM 2 series devices.
- Home
- Technology
- News
YubiKeys have an unfixable security flaw
Security researchers have detected a vulnerability in YubiKey two-factor authentication tokens that enables attackers to clone the device if they get their hands on it.


YubiKey manufacturer Yubico says the severity of the side-channel vulnerability is “moderate” but is difficult to exploit, partly because two-factor systems rely upon something the user has and something only they should know.
“The attacker would need physical possession of the YubiKey, Security Key, or YubiHSM, knowledge of the accounts they want to target, and specialized equipment to perform the necessary attack,” the company said in its security advisory. “Depending on the use case, the attacker may also require additional knowledge including username, PIN, account password, or authentication key.” But those aren’t necessarily deterrents to a highly motivated individual or state-sponsored attack.
As YubiKey firmware can’t be updated, all YubiKey 5 devices before version 5.7 (or 5.7.2 for the Bio series and 2.4.0 for YubiHSM 2) will remain vulnerable forever. Later model versions aren’t affected as they no longer use the Infineon cryptolibrary. NinjaLab, the security firm that discovered the vulnerability, estimates that it's existed in Infineon’s top security chips for over 14 years. The researchers believe other devices using the Infineon cryptographic library or Infineon’s SLE78, Optiga Trust M, and Optiga TPM microcontrollers are also at risk.
.jpg&w=3840&q=75)
PM Shehbaz Sharif again invites opposition for dialogue on charter of democracy and charter of economy
- 9 گھنٹے قبل

Disclosure Day pits aliens against religion. But faith leaders are ready to believe.
- 15 گھنٹے قبل

OpenAI files for IPO, following Anthropic
- 17 گھنٹے قبل

Trump’s strange flirtation with AI socialism, explained
- 15 گھنٹے قبل

Chairman PM Youth Programme assures full support for Punjab University's Film Department.
- 2 گھنٹے قبل

Ishaq Dar’s telephonic contact with Egyptian foreign minister;exchange of views on latest regional situation
- 7 گھنٹے قبل

PM lauds support of Qatar for Pakistan’s peace efforts
- 2 گھنٹے قبل

Iran-US peace agreement to be finalized within 24 hours,says Prime Minister Shehbaz Sharif
- 6 گھنٹے قبل

North Waziristan: Security forces kill 21 more militants, total death toll reaches 48
- 9 گھنٹے قبل

Apple is using AI to fix Safari’s extension problem
- 17 گھنٹے قبل

Apple announces iOS 27
- 17 گھنٹے قبل

WWDC protesters want Apple to ban Elon Musk’s apps
- 17 گھنٹے قبل












.webp&w=3840&q=75)