New Passkey Attacks Threaten Security of Synced Private Keys and MFA Systems
Recent research has uncovered vulnerabilities in passkey systems that could allow attackers to bypass security measures without breaking the underlying cryptography. These attacks exploit weaknesses in Windows and Google Password Manager, allowing unauthorized access to private keys and bypassing multifactor authentication (MFA). The vulnerabilities involve reusing signed authentication material, exploiting cloud-synced passkey systems, and using compromised user sessions to access Windows Hello for Business keys. Microsoft has issued a security update to address these issues, and researchers continue to explore the implications of these findings.