New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Overview
Recent research has shown vulnerabilities in passkey systems designed to enhance online security by replacing traditional passwords and resisting phishing attacks. Three separate studies demonstrated methods for bypassing these protections without breaking the underlying cryptography. For instance, attackers were able to exploit signed authentication data exposed by Windows, leverage a cloud-synced passkey system compromised by existing malware on a victim's device, and other techniques. This is concerning for users and organizations relying on passkeys for secure authentication, as it suggests that even advanced security measures can be undermined. As these attacks become more sophisticated, it raises questions about the reliability of passkeys and the need for ongoing vigilance in security practices.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Passkeys, Windows authentication systems, cloud-synced passkey services
- Action Required: Users should review their security settings, ensure their devices are free from malware, and consider additional security measures beyond passkeys.
- Timeline: Newly disclosed
Original Article Summary
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a
Impact
Passkeys, Windows authentication systems, cloud-synced passkey services
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should review their security settings, ensure their devices are free from malware, and consider additional security measures beyond passkeys.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Windows, Phishing, Microsoft, and 2 more.