Passkey Security: New Attacks and How to Protect Yourself (2026)

Passkeys, the new authentication method designed to replace passwords and resist phishing, have been found to have vulnerabilities that could be exploited by attackers. Three separate research efforts have demonstrated ways to defeat passkey protections without breaking the underlying cryptography. These attacks reuse signed authentication material, abuse cloud-synced passkey systems, and use compromised user sessions to bypass phishing-resistant MFA.

The impact of these attacks varies. SpecterOps demonstrated a Windows and Microsoft Entra ID chain that could impersonate privileged users, reusing signed authentication material rather than stealing the authenticator's private key. Unit 42 showed attacks against Google Password Manager in Chrome, including a path that recovers the private keys for a victim's synced passkeys. Independent researcher Dirk-jan Mollema showed that malware already running in a signed-in Windows session can use a hardware-bound Windows Hello for Business key without a fresh PIN or biometric check.

The fixes and mitigations for these vulnerabilities differ. Microsoft's Windows logging vulnerability, CVE-2026-34348, has a vendor CVSS score of 6.5 and a security update. Microsoft has also applied mitigations for the reported issue involving passkey relay assertions. However, the company's response did not provide technical details about the scope of the separate Entra-side mitigations.

The findings of Unit 42 and Mollema also highlight the limitations of passkeys. No single choice between synced and device-bound passkeys can completely close the broader attack surface. The attacks begin with malware already on the endpoint or inside an already compromised user session, showing what passkeys may fail to contain after endpoint compromise.

To mitigate these vulnerabilities, Windows users should install Microsoft's applicable security updates for CVE-2026-34348. Services accepting WebAuthn assertions should enforce user-verification requirements. Endpoint defenses need to treat passkey stores, recovery flows, and browser memory as credential-sensitive territory. Entra defenders should monitor unusual Windows Hello for Business authentications and unexpected device registrations.

Microsoft is increasing the stakes for getting implementation details right. Starting September 1, 2026, Entra ID users currently enabled for SMS or voice authentication will be automatically enabled for passkeys and nudged to register them. Microsoft-provided SMS and voice delivery is scheduled to retire on February 1, 2027. This transition highlights the importance of adopting phishing-resistant authentication methods and maintaining endpoint protections through a Zero Trust security model.

Passkey Security: New Attacks and How to Protect Yourself (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Annamae Dooley

Last Updated:

Views: 6392

Rating: 4.4 / 5 (65 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Annamae Dooley

Birthday: 2001-07-26

Address: 9687 Tambra Meadow, Bradleyhaven, TN 53219

Phone: +9316045904039

Job: Future Coordinator

Hobby: Archery, Couponing, Poi, Kite flying, Knitting, Rappelling, Baseball

Introduction: My name is Annamae Dooley, I am a witty, quaint, lovely, clever, rich, sparkling, powerful person who loves writing and wants to share my knowledge and understanding with you.