New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Read original article ↗AI Summary
Recent research from SpecterOps, Unit 42, and independent researcher Dirk-jan Mollema reveals multiple attack vectors against passkey-based authentication systems despite their strong underlying cryptography. SpecterOps demonstrated a 'Pass-the-Passkey' attack leveraging CVE-2026-34348, where Windows stored YubiKey signatures in cleartext, enabling replay attacks that bypass phishing-resistant MFA in Microsoft Entra ID. Unit 42's 'Pass-ta-key' research shows how malware can extract or abuse Google Password Manager's synced passkeys by recovering the Security Domain Secret from memory, allowing recovery of private keys. Mollema's work reveals that malware in a compromised Windows session can use Windows Hello for Business keys without re-authenticating via PIN or biometrics, enabling unauthorized sign-ins to Entra ID. These findings highlight implementation flaws surrounding passkey systems rather than cryptographic weaknesses.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.