CVE Tools
Back to feed
Research Windows Hello for Business phishing Google Password Manager Microsoft

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

The Hacker News·By The Hacker News··6 min read
CVE Tools coverage

Recent research from SpecterOps, Unit 42, and independent researcher Dirk-jan Mollema highlights distinct methods to undermine passkey-based authentication for Microsoft and Google products. These techniques exploit implementation weaknesses in Windows Event Logging (tracked as CVE-2026-34348) and the Chrome browser’s handling of synced credentials, allowing attackers to impersonate users or retrieve private keys without cracking FIDO2 cryptography. While these represent significant risks to phishing-resistant MFA, no active in-the-wild exploitation has been confirmed yet. Organizations should apply relevant Microsoft security updates and review endpoint defenses against unauthorized access to browser memory and local authentication materials.