< Back to situation

[REVISION HISTORY]

Passkey technology adoption and security research

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-08-11 12:09 UTC → 2026-08-16 06:50 UTC · added removed

Passkey technology has seen widespread adoption, with approximately five million users globally and high consumer awareness. For enterprises, the technology has demonstrated the ability to reduce help-desk tickets related to password issues by as much as 60%. New specifications have also been proposed to create an interoperable format for storing passkey credentials, which aims to simplify server-side integration. However, cybersecurity research has identified vulnerabilities in how passkeys are implemented and managed. These findings indicate that while the underlying cryptography remains secure, flaws in authentication chains—such as those involving Windows and Microsoft Entra ID—can allow for user impersonation. Researchers have also identified methods to recover private keys within Google Password Manager and noted that malware in active sessions can sometimes utilize hardware-bound keys without additional biometric checks. Experts have clarified that these risks often stem from storage methods; because FIDO 2 specifications do not mandate hardware-based storage, many platforms store passkeys locally to facilitate cross-device syncing, creating an attack surface for malware already present on a system. Recent studies have expanded on these risks. Research from Palo Alto Networks’ Unit 42 indicates that malware can exploit passkey workflows, device sharing, and account recovery processes, sometimes bypassing biometric or PIN requirements by leveraging trust from previously registered devices. Furthermore, a Cornell University study presented at the USENIX Security Symposium highlighted limitations within the FIDO2 architecture, demonstrating that an attacker with temporary physical or technical access to a device could potentially register their own credentials. These findings suggest that security strategies must evolve to manage device context, token lifecycles, and user control to prevent unauthorized access.

Versions

  1. 2026-08-16 06:50 UTC Passkey technology adoption and security research
  2. 2026-08-11 12:09 UTC Passkey technology adoption and security research

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.