Skip to content

Three research papers bypass phishing-resistant passkey authentication

Bottom line: Three independent research papers show that phishing-resistant passkey authentication in Windows, Entra ID and Google Password Manager can be bypassed through implementation weaknesses, without attacking the cryptography itself.

At Black Hat USA and in accompanying analyses, security researchers showed that passkey protection mechanisms in Windows, Microsoft Entra ID and Google Password Manager can be circumvented without breaking the underlying cryptography. This affects precisely those environments that use passkeys as a replacement for classic, phishing-prone MFA methods.

Security researcher Michael Grafnetter of SpecterOps presented his research “Pass-the-Passkey” at Black Hat USA on August 5. According to the findings, Windows stored previous YubiKey signatures in plaintext, where they could also be read by authenticated, non-privileged users – including remote users. Combined with weaknesses in passkey validation in Microsoft Entra ID, this made it possible to impersonate privileged users even though phishing-resistant multi-factor authentication was mandated. The attacker does not need the private key of an authentication device, but merely an already generated signature retained by Windows. The Windows vulnerability is tracked as CVE-2026-34348; Microsoft has released a security update and confirmed to The Hacker News additional mitigations against the reported forwarding of passkey confirmations.

Researchers from Unit 42 demonstrated several attacks in their study “Pass-ta-key” against the cloud-based, synchronized passkey system of Google Password Manager in Chrome on Windows – each requiring that malware is already running on the target device. The most severe variant, “Golden Pass-ta-key”, targets the Security Domain Secret, a 32-byte master key used to protect synchronized passkeys. Unit 42 initially found this secret exposed in Chrome’s device logging; Google removed it from this log output after the disclosure. However, according to the researchers, the secret remains temporarily visible in Chrome’s process memory during a re-registration of a device, allowing the private keys of all of a victim’s synchronized passkeys to be reconstructed. Since Google currently offers no rotation or revocation mechanism for this secret, such a compromise is significantly more long-lived than the theft of a single credential.

Independent researcher Dirk-jan Mollema investigated Windows Hello for Business in parallel, whose underlying key is normally protected by the Trusted Platform Module on modern Windows devices and is non-exportable. He found that a low-privileged process within an already compromised, logged-in Windows session can use this non-exportable key without requiring a renewed PIN or biometric input. Because the associated WebAuthn challenge from Entra ID is valid for five minutes and is bound neither to a session nor to a specific user or tenant, a challenge requested on the attacker’s system can be signed on the victim’s device and returned as a valid, phishing-resistant sign-in.

For Windows systems, prompt installation of the security update for CVE-2026-34348 is recommended. Services that accept WebAuthn confirmations should consistently enforce requested user verifications – as the online marketplace eBay has already remediated following a report from Unit 42. Endpoint protection solutions should treat passkey storage, recovery flows and browser memory as particularly sensitive areas requiring protection. For Entra environments, targeted monitoring of unusual Windows Hello for Business sign-ins without a device identifier, as well as unexpected device registrations, is additionally recommended.


Source: www.it-daily.net · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: