< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Passkey security vulnerabilities identified by researchers

Security researchers have identified vulnerabilities in passkey authentication methods that could allow attackers to take over accounts under specific conditions. While passkeys are designed to be more secure than traditional passwords by eliminating the need for secret credentials and reducing phishing risks, recent studies suggest they are not immune to exploitation if a device is already compromised.

Research from Palo Alto Networks' Unit 42 indicates that malware running on a victim's device can exploit passkey workflows, device sharing, and account recovery processes. In some scenarios, attackers can bypass biometric or PIN requirements by leveraging the trust established by a previously registered device.

Additionally, a study from Cornell University presented at the USENIX Security Symposium highlights limitations within the FIDO2 architecture. The researchers demonstrated that an attacker with temporary physical or technical access to a device could potentially register their own access credentials. The findings suggest that security strategies must evolve from simply replacing passwords with passkeys to managing the broader device context, token lifecycles, and user control to prevent unauthorized access.

Entities

Cornell University · FIDO Alliance · Palo Alto Networks · Unit 42