< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

3 clusters · 5 sources · 26 days · First seen · Last updated

Passkey technology adoption and security research

Overview

Passkey technology has seen widespread adoption, with approximately five million users globally and high consumer awareness. For enterprises, the technology has demonstrated the ability to reduce help-desk tickets related to password issues by as much as 60%. New specifications have also been proposed to create an interoperable format for storing passkey credentials, which aims to simplify server-side integration.

However, cybersecurity research has identified vulnerabilities in how passkeys are implemented and managed. These findings indicate that while the underlying cryptography remains secure, flaws in authentication chains—such as those involving Windows and Microsoft Entra ID—can allow for user impersonation. Researchers have also identified methods to recover private keys within Google Password Manager and noted that malware in active sessions can sometimes utilize hardware-bound keys without additional biometric checks.

Experts have clarified that these risks often stem from storage methods; because FIDO 2 specifications do not mandate hardware-based storage, many platforms store passkeys locally to facilitate cross-device syncing, creating an attack surface for malware already present on a system.

Recent studies have expanded on these risks. Research from Palo Alto Networks’ Unit 42 indicates that malware can exploit passkey workflows, device sharing, and account recovery processes, sometimes bypassing biometric or PIN requirements by leveraging trust from previously registered devices. Furthermore, a Cornell University study presented at the USENIX Security Symposium highlighted limitations within the FIDO2 architecture, demonstrating that an attacker with temporary physical or technical access to a device could potentially register their own credentials. These findings suggest that security strategies must evolve to manage device context, token lifecycles, and user control to prevent unauthorized access.

Entities

FIDO Alliance · Palo Alto Networks · Google · Unit 42 · Microsoft

Timeline

  1. 1 day ago

    [TECHNOLOGY] 2 sources
    Passkey security vulnerabilities identified by researchers

    Researchers from Palo Alto Networks and Cornell University have identified ways attackers can bypass passkey security and take over accounts if a user's device is already infected or physically accessed.

  2. 7 days ago

    [TECHNOLOGY] 3 sources
    Passkey security research reveals vulnerabilities in authentication implementations

    Researchers have demonstrated new ways to bypass passkey protections by exploiting how authentication material is reused, synced, or stored on devices, rather than breaking the underlying cryptography.

  3. 27 days ago

    [TECHNOLOGY] 2 sources
    Passkeys Adoption Cuts Helpdesk Requests by Up to 60%

    Passkeys are used by about five million people, known by 90% of consumers, and can slash password‑related helpdesk tickets by up to 60%; a new interoperable record format aims to simplify implementation.

Sources

arstechnica.com · b2b-cyber-security.de · cybernoz.com · it-boltwise.de · thehackernews.com

This summary has been updated 1 time: see revision history