Fresh Passkey Flaws Threaten MFA Across Windows, Chrome, and Entra ID

TL;DR Summary
Three independent groups revealed passkey-related attack vectors that don’t break cryptography: exploiting exposed Windows-stored signed data to impersonate privileged users via Entra ID, compromising Google Password Manager’s synced passkeys in Chrome to recover private keys, and abusing a compromised Windows session to use a Windows Hello for Business key for new WebAuthn assertions. Impacts vary, with mitigations including CVE-2026-34348 fixes, enforcing user-verification for WebAuthn, and strengthened endpoint/zero-trust protections; no single fix exists since issues lie in surrounding controls, not math.
Topics:technology#chrome#passkeys#phishing-resistant-mfa#security#webauthn#windows-hello-for-business
- New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA thehackernews.com
- Pass the Passkey: A Novel Attack Surface in Passwordless Authentication Unit 42
- Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks Malwarebytes
- Google Password Manager passkeys could be at risk with new ‘Pass-ta-key’ attack 9to5Google
- Millions of Google accounts could be under attack, researchers warn GB News
Reading Insights
Total Reads
0
Unique Readers
17
Time Saved
6 min
vs 7 min read
Condensed
94%
1,265 → 80 words
Want the full story? Read the original article
Read on thehackernews.com