New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
AI-summarised brief · reviewed before publication
Three independent research teams exposed ways to bypass passkey authentication without breaking its underlying cryptography. The attacks exploited Windows Event Logging Service data, a cloud‑synced passkey system in Google Password Manager, and a compromised Windows Hello for Business key. Microsoft issued a patch for CVE‑2026‑34348 and applied mitigations for passkey relay assertions, while Google removed the exposed Security Domain Secret from logs but left it in memory. The findings highlight that passkeys remain vulnerable to replay and credential‑recovery attacks.
💡 Why It Matters
- · The revelations show that even phishing‑resistant MFA can be subverted through side‑channel data leaks, forcing vendors to tighten logging and memory handling.
- · This underscores the need for continuous scrutiny of authentication protocols beyond their cryptographic foundations.