New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
AI Generated Image

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

The Hacker News technology

Key Points:

  • Three recent research efforts revealed methods to bypass passkey protections without breaking their underlying cryptography, exploiting weaknesses in Windows, Microsoft Entra ID, and Google Password Manager systems.
  • SpecterOps found that Windows stored signed authentication signatures in cleartext, allowing attackers to impersonate privileged users by replaying these signatures, tracked as CVE-2026-34348, with Microsoft issuing security updates and mitigations.
  • Unit 42 demonstrated malware on victim machines could abuse Google Password Manager's synced passkeys by extracting a master key from Chrome, enabling recovery of private keys and persistent compromise due to lack of key rotation.
  • Researcher Dirk-jan Mollema showed that malware running in a compromised Windows session can use Windows Hello for Business keys without user re-authentication, exploiting validation flaws in Microsoft Entra ID to bypass phishing-resistant multifactor authentication.
  • Microsoft recommends installing security updates, enforcing strict user verification, adopting least-privilege access, and embracing Zero Trust models; starting September 2026, Entra ID users will be nudged to register passkeys as SMS and voice authentication retire in early 2027.

Trending Business

Trending Technology

Trending Health