New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Key Points:
- Three recent research efforts revealed methods to bypass passkey protections without breaking their underlying cryptography, exploiting weaknesses in Windows, Microsoft Entra ID, and Google Password Manager systems.
- SpecterOps found that Windows stored signed authentication signatures in cleartext, allowing attackers to impersonate privileged users by replaying these signatures, tracked as CVE-2026-34348, with Microsoft issuing security updates and mitigations.
- Unit 42 demonstrated malware on victim machines could abuse Google Password Manager's synced passkeys by extracting a master key from Chrome, enabling recovery of private keys and persistent compromise due to lack of key rotation.
- Researcher Dirk-jan Mollema showed that malware running in a compromised Windows session can use Windows Hello for Business keys without user re-authentication, exploiting validation flaws in Microsoft Entra ID to bypass phishing-resistant multifactor authentication.
- Microsoft recommends installing security updates, enforcing strict user verification, adopting least-privilege access, and embracing Zero Trust models; starting September 2026, Entra ID users will be nudged to register passkeys as SMS and voice authentication retire in early 2027.