New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Recent research from SpecterOps, Unit 42, and independent researcher Dirk-jan Mollema highlights distinct methods to undermine passkey-based authentication for Microsoft and Google products. These techniques exploit implementation weaknesses in Windows Event Logging (tracked as CVE-2026-34348) and the Chrome browser’s handling of synced credentials, allowing attackers to impersonate users or retrieve private keys without cracking FIDO2 cryptography. While these represent significant risks to phishing-resistant MFA, no active in-the-wild exploitation has been confirmed yet. Organizations should apply relevant Microsoft security updates and review endpoint defenses against unauthorized access to browser memory and local authentication materials.