New Passkey Attacks Expose Private Keys and Bypass Phishing-Resistant MFA Without Breaking Encryption
Security researchers have identified new attack vectors that target the software and cloud processes surrounding passkeys, rather than the underlying cryptography. These attacks require local access to a Windows endpoint to bypass MFA or steal credentials.
Why it matters
It highlights that while passkeys are more secure than passwords, they are still vulnerable to sophisticated endpoint-based malware and implementation flaws.
Three independent security investigations have exposed weaknesses in the systems surrounding passkeys, demonstrating how attackers with access to a Windows endpoint could impersonate users, bypass phishing-resistant multifactor authentication or recover the private keys behind cloud-synchronised credentials.
The findings do not undermine the public-key cryptography at the heart of FIDO2 and WebAuthn. Instead, the researchers targeted the software, cloud services, recovery processes and operating-system interfaces responsible for creating, storing and using passkeys.
The distinction is important. Passkeys remain substantially more resistant to conventional phishing, credential stuffing and password-database theft than passwords. However, the new research shows that an attacker may not need to defeat their cryptography if malware can make a legitimate authenticator sign data, steal an earlier signed assertion, manipulate a cloud authenticator or obtain a master secret while it is exposed in browser memory.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in