CYBERSECURITYTRACKER
TRACKING7,631 stories in this site build1,635 vulnerability news stories in this site build
Permanent story citation

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4132

As cited

Copy frozen at (site build).

vulnerabilities

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Researchers have demonstrated three separate attacks that can defeat passkey protections without breaking the underlying cryptography, including reusing signed authentication material and abusing cloud-synced passkey systems. These attacks can potentially recover synced private keys or bypass phishing-resistant multi-factor authentication (MFA). The passkey system is designed to replace reusable passwords and resist phishing attempts.

Why it matters: Practitioners using passkey protections, especially those with cloud-synced systems, should be aware of these vulnerabilities and take steps to mitigate them to prevent potential private key exposure or MFA bypass.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Three separate research efforts disclosed attacks that circumvent passkey protections by reusing exposed authentication material from Windows, exploiting cloud-synced passkey systems from compromised devices, and leveraging additional attack vectors. These attacks defeat passkey security without breaking the underlying cryptography. Passkeys are promoted as replacements for passwords and as phishing-resistant, but these findings expose practical weaknesses in their implementation and deployment.

Why it matters: Security teams deploying passkeys as a primary authentication defense need to understand that implementation flaws, device compromise, and signed material exposure can undermine their phishing-resistance claims; practitioners should review how passkeys are synced, stored, and validated in their environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Three separate research efforts disclosed attacks that circumvent passkey protections by reusing exposed authentication material from Windows, exploiting cloud-synced passkey systems from compromised devices, and leveraging additional attack vectors. These attacks defeat passkey security without breaking the underlying cryptography. Passkeys are promoted as replacements for passwords and as phishing-resistant, but these findings expose practical weaknesses in their implementation and deployment.

Why it matters: Security teams deploying passkeys as a primary authentication defense need to understand that implementation flaws, device compromise, and signed material exposure can undermine their phishing-resistance claims; practitioners should review how passkeys are synced, stored, and validated in their environments.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary