fix(passkeys): validate caller origin before signing WebAuthn assertions
details
- Finding IDs
- F-PROTON-ANDROID-PASS-PASSKEY-ORIGIN-001
- Status
- fixed publicly in 1.40.0 (F-Droid 1.39.2 still behind)
- Reported via
- security contact
- Note
- public Proton Pass Android commit 855c602584bd adds PasskeyOriginVerifier, Digital Asset Links validation, and passkey_privileged_browsers_allowlist.json before signing WebAuthn assertions. Play/APKMirror/APKPure 1.40.0 builds contain the fix; F-Droid was still on 1.39.2 at verification time and therefore should not be treated as fixed until it updates.
F-PROTON-ANDROID-PASS-PASSKEY-ORIGIN-001: Access control. The signing request does not establish the caller's authorized WebAuthn origin. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-PROTON-ANDROID-PASS-PASSKEY-ORIGIN-001
Security area (1seal assessment): Identity. Passkey assertions require validation of the calling app or browser origin against trusted associations. Reviewed 21 Sep 2026.