New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Recent research has revealed significant vulnerabilities in passkey authentication systems, demonstrating ways to bypass security measures and impersonate users. SpecterOps found that Windows stored past YubiKey signatures in cleartext, allowing attackers to chain those signatures with weaknesses in Microsoft Entra ID for privileged user impersonation. Unit 42 discovered malware could recover synced passkey private keys by exploiting Chrome's device identity machinery and a leaked Security Domain Secret. Additionally, a low-privilege process within a compromised Windows session can leverage a hardware-bound Windows Hello for Business key to generate fresh authentication material. These vulnerabilities highlight that passkeys are not a complete solution and require robust security practices beyond the authentication method itself.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
