Summary
Researchers have discovered novel attack vectors that can recover synced passkey private keys or bypass phishing-resistant multi-factor authentication (MFA), undermining one of the strongest defenses against credential theft attacks. The attacks target passkey synchronization mechanisms \u2014 the protocols that allow passkeys to be synced across devices \u2014 enabling attackers to extract private keys from synced devices or bypass the phishing-resistant properties that make passkeys superior to traditional MFA methods.
The first attack vector targets passkey synchronization services, allowing attackers who gain access to a synced device to extract the private keys used for authentication. The second vector exploits weaknesses in how certain passkey implementations handle phishing resistance, allowing attackers to craft authentication requests that bypass the intended security guarantees. Both attacks represent significant challenges to the security model that passkeys were designed to provide.
Source: The Hacker News
Why This Matters
Passkeys were heralded as the future of authentication, offering phishing-resistant MFA without the usability burdens of traditional methods. These new attack vectors undermine that promise by exploiting the synchronization infrastructure that makes passkeys convenient across devices. If private keys can be recovered from synced devices, or if phishing resistance can be bypassed, the fundamental value proposition of passkeys is compromised.
Who is impacted: All organizations that have deployed or are considering passkey-based authentication, particularly those relying on cross-device synchronization features. Enterprises, government agencies, and consumer services that have invested in passkey infrastructure face a significant reassessment of their authentication strategies.
Actionable steps: Organizations deploying passkeys should review their synchronization settings to minimize the attack surface, consider using local-only passkey storage where cross-device sync is not required, and monitor for any indicators of passkey compromise. Security teams should stay informed about vendor responses to these vulnerabilities and consider implementing additional authentication layers for high-value accounts until passkey implementations are fully hardened.
