New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Researchers demonstrated three new attacks that can recover synced passkeys or bypass phishing-resistant MFA without breaking the underlying cryptography, exploiting Windows-exposed authentication material and cloud-synced passkey systems via malware.
New passkey attacks can recover synced private keys or bypass phishing-resistant multi-factor authentication, according to three separate research efforts last week. The exploits do not break the underlying cryptography. Instead, one attack reused signed authentication material exposed by Windows. Another abused a cloud-synced passkey system via malware already on the victim’s machine. The third method used a man-in-the-middle approach to intercept passkey exchanges. These findings undermine passkeys’ core promise of replacing reusable passwords and resisting phishing, highlighting new vulnerabilities in their implementation.