< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-10T17:55:04+05:30

Exploiting Passkey Vulnerabilities: Recovery of Synced Private Keys and Bypassing Phishing-Resistant MFA

Three research groups identified vulnerabilities in passkey systems that allow recovery of synced private keys and bypassing phishing-resistant MFA without breaking underlying cryptography. The attacks exploit implementation flaws in Windows, Google Password Manager, and Windows Hello for Business, highlighting risks in cloud-synced and device-bound authentication methods.

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.

Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a 

Read original article

*** END OF TRANSMISSION ***