Three recent research efforts revealed attacks bypassing passkey security without breaking underlying cryptography by exploiting implementation flaws in Windows and Google Chrome. These include Windows exposing signed authentication assertions allowing privileged user impersonation (CVE-2026-34348), malware recovering private keys from Google's synced passkeys in Chrome via leaked master secrets, and malware abusing Windows Hello for Business keys without user verification to satisfy phishing-resistant MFA. Microsoft and Google have issued mitigations and updates, but attackers with endpoint access can still leverage these weaknesses, emphasizing the need for endpoint protections and strict enforcement of authentication policies.
https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html

