Skip to main content

Researchers disclose vulnerability in Windows Hello facial recognition

Researchers at the security firm CyberArk Labs have discovered a vulnerability in Microsoft’s Windows Hello facial recognition system in Windows 10 and Windows 11. Calling it a “design flaw,” the researchers say that hackers can get around Windows Hello by using a certain type of hardware to eventually gain access to your PC.

Though it isn’t exactly something that is easily accomplished (and Microsoft says it has mitigated the vulnerability), there’s a very specific set of conditions that can lead to the bypassing. In all cases, hackers would need to capture an IR image of the victim’s face, have physical access to the victim’s PC, and also use a custom USB device that can impersonate a camera. CyberArk Labs describe the six-part process on its website, with a video showing the proof-of-concept.

A six step diagram showing the vulnerability in Windows Hello.
Image used with permission by copyright holder

Per the firm, this is all possible because Windows Hello will only process IR camera frames when trying to authenticate a user. “One would need to implement a USB camera that supports RGB and IR cameras. This USB device then only needs to send genuine IR frames of the victim to bypass the login phase, while the RGB frames can contain anything,” said CyberArk’s Omer Tsarfati.

Recommended Videos

There currently is no evidence that this vulnerability has been actively used, but CyberArk Labs warns that someone with the right skills can use this to target journalists and others with sensitive content on their devices. It is also important to note that the research was done on Windows Hello for Business and not the consumer version of Windows Hello. There is still, though, the chance that this vulnerability could apply to other security systems where a third-party USB camera is used as a biometric sensor.

Please enable Javascript to view this content

CyberArk labs submitted this vulnerability to Microsoft back on March 23, 2021. Microsoft acknowledged this issue a day later. Microsoft has since assigned a CVE for the issue, sharing mitigation via a security update on July 13.

According to Microsoft, this patch mitigated the issue and Windows Hello Enhanced Sign-in Security can protect against such attacks. CyberArk, though, points out that the mitigation depends on having devices with specific cameras, and the “inherent to system design, implicit trust of input from peripheral devices remains.” An investigation is still ongoing.

Arif Bacchus
Arif Bacchus is a native New Yorker and a fan of all things technology. Arif works as a freelance writer at Digital Trends…
Windows 11 Recall finally arrives, but with one new problem
Recall screenshot.

The Windows 11 Recall feature has been troublesome since its announcement. Now that the feature is available in a testing capacity, it is still causing users some issues.

Tech reviewers testing the feature have observed that Recall will now fail to save the snapshots that allow the function to work. CNBC noted that it may take “several minutes” for a snapshot to save, which may leave delays in the AI processing. Tom Warren of The Verge, noted on Bluesky that snapshots were not saving at all in his experience.

Read more
Windows 11 remains the driver of growth in PCs, not AI
The Surface Laptop shown in front of a Copilot+ sign.

There's been a lot of talk about AI PCs this year, but has it actually delivered on its promise? A new analysis from TrendForce says the significant boost in laptop sales in 2024 has more to do with Windows 11 updates than it does with fancy new AI features.

"The impact of AI-integrated notebooks on the overall market remains limited for now," the report states. "However, AI features are expected to naturally integrate into notebook specifications as brands gradually incorporate them, resulting in a steady rise in the penetration rates of AI notebooks."

Read more
Microsoft warns that the latest Windows 11 update may crash PC games now
Gaming PC on a desk.

Microsoft has once again temporarily halted the rollout of its latest major Windows 11 update, also known as 24H2. This time it is for systems running select Ubisoft games following widespread user reports of crashes and performance issues. The affected titles include Assassin's Creed Valhalla, Assassin's Creed Origins, Assassin's Creed Odyssey, Star Wars Outlaws, and Avatar: Frontiers of Pandora.

Common complaints include black screens, freezing, and unresponsiveness during gameplay or while loading these titles. "I just bought a new gaming laptop with RTX 4080, Intel i9 14900hx. I can't play the game (Origins) even for 5 minutes because it crashes to a black screen, with audio, and the only way to close it is from task manager. Impossible to play," one user shared on Reddit. Others reported similar frustrations, citing the persistent error “NTDLL.dll” that renders their games unplayable.

Read more