CVE Tools

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

The Hacker NewsBy The Hacker News

ResearchWindows Hello for BusinessGoogle Password Manager

Our summary

Recent research from SpecterOps, Unit 42, and independent researcher Dirk-jan Mollema highlights distinct methods to undermine passkey-based authentication for Microsoft and Google products. These techniques exploit implementation weaknesses in Windows Event Logging (tracked as CVE-2026-34348) and the Chrome browser’s handling of synced credentials, allowing attackers to impersonate users or retrieve private keys without cracking FIDO2 cryptography. While these represent significant risks to phishing-resistant MFA, no active in-the-wild exploitation has been confirmed yet. Organizations should apply relevant Microsoft security updates and review endpoint defenses against unauthorized access to browser memory and local authentication materials.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store