Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

Security researchers have uncovered new attack vectors targeting passwordless authentication systems, specifically Google's synced passkey ecosystem. The research demonstrates how malware can bypass user verification and extract private keys, challenging the perceived invulnerability of passkeys.
This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. We show how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in