Passkey Vulnerabilities Allow Attackers to Bypass MFA and Recover Synced Private Keys
Researchers have discovered vulnerabilities in passkey systems that allow attackers to bypass phishing-resistant multifactor authentication (MFA) and recover synced private keys. The vulnerabilities were found in three separate research efforts last week, including a Windows and Microsoft Entra ID chain, Google Password Manager's synced-passkey system, and Windows Hello for Business.
The attacks do not rely on breaking the underlying cryptography but instead exploit weaknesses in surrounding controls. For example, Unit 42 demonstrated that malware can manipulate client trust and user-verification handling to obtain signatures needed to act like a legitimate Google Password Manager client. Mollema showed that software inside a live Windows session can use a legitimate hardware-bound key to create fresh authentication material.
Microsoft has issued a security update for CVE-2026-34348, an information-disclosure vulnerability in the Windows Event Logging Service, and applied mitigations for the reported issue involving passkey relay assertions. The company recommends adopting a least-privilege access approach, using phishing-resistant authentication methods, and maintaining endpoint protections by embracing a Zero Trust security model.