Fresh Passkey Flaws Threaten MFA Across Windows, Chrome, and Entra ID

1 min read
Source: thehackernews.com
Fresh Passkey Flaws Threaten MFA Across Windows, Chrome, and Entra ID
Photo: thehackernews.com
TL;DR Summary

Three independent groups revealed passkey-related attack vectors that don’t break cryptography: exploiting exposed Windows-stored signed data to impersonate privileged users via Entra ID, compromising Google Password Manager’s synced passkeys in Chrome to recover private keys, and abusing a compromised Windows session to use a Windows Hello for Business key for new WebAuthn assertions. Impacts vary, with mitigations including CVE-2026-34348 fixes, enforcing user-verification for WebAuthn, and strengthened endpoint/zero-trust protections; no single fix exists since issues lie in surrounding controls, not math.

Share this article

Reading Insights

Total Reads

0

Unique Readers

17

Time Saved

6 min

vs 7 min read

Condensed

94%

1,26580 words

Want the full story? Read the original article

Read on thehackernews.com