Pass-the-Passkey Attack Lets Adversaries Impersonate Users and Bypass MFA in Windows 11, Entra ID
Image: Unit 42

Pass-the-Passkey Attack Lets Adversaries Impersonate Users and Bypass MFA in Windows 11, Entra ID

03 August, 2026.Technology and Science.14 sources

Malware can hijack Google-synced passkeys to impersonate enterprise users. Pass-the-Passkey techniques bypass phishing-resistant MFA on Windows 11 and Entra ID.

14 outlets1 divide1 fact unevenly covered

Full story

Pass-the-Passkey chain

Security researchers described a new attack family called “Pass-the-Passkey” that enables adversaries to impersonate enterprise users and bypass phishing-resistant multi-factor authentication (MFA) protections in Windows 11 and Microsoft Entra ID environments.

a new attack family named “Pass-the-Passkey”

GBHackers NewsGBHackers News

The research says the attack does not involve extracting a passkey’s private cryptographic key from a FIDO2 security key, Windows Hello container, or other trusted hardware, and instead exploits weaknesses in WebAuthn implementation and validation workflow.

Image from 9to5Google
9to5Google9to5Google

Researchers at SpecterOps found that Windows 11 could log complete WebAuthn assertion responses in the Microsoft-Windows-WebAuthN/Operational event log, and that in certain scenarios low-privilege users, and sometimes even remote users with access to the event log, could retrieve assertion data generated during another user’s passkey login.

The second part of the attack chain relates to Microsoft Entra ID’s server-side passkey validation, where the research says Entra ID did not adequately enforce key WebAuthn anti-replay controls including challenge uniqueness, session binding, and signature-counter verification.

Microsoft has reportedly addressed the Windows logging issue, tracked as CVE-2026-34348, by truncating logged signatures as of July 2026.

What Microsoft and SpecterOps say

A Microsoft spokesperson told The Hacker News that the company has applied mitigations for the reported issue involving passkey relay assertions and recommended “adopting a least-privilege access approach, using phishing-resistant authentication methods, and maintaining endpoint protections by embracing a Zero Trust security model.”

The Hacker News also quoted SpecterOps saying it has not retested the Entra replay vulnerability since June, but that the firm now considers the full Windows-to-Entra vulnerability chain broken because Microsoft’s July 2026 Windows updates make the WebAuthn assertions written to event logs unusable for replay attacks.

Image from Ars Technica
Ars TechnicaArs Technica

The research described by GBHackers News says the Windows exposure was assigned CVE-2026-34348 as an information-disclosure vulnerability in the Windows Event Logging Service, with Microsoft giving it a CVSS 3.1 score of 6.5.

Ars Technica reported that Palo Alto Networks researcher Arie Olshtein described “Pass-ta-key” as a novel attack surface, but Ars Technica said the attacks demonstrated in the post are neither novel nor unique to passkeys.

Ars Technica also noted that FIDO 2 specifications do not mandate that passkeys be kept in TPMs, and that virtually the lone holdout is Microsoft, which gives users the option to store passkeys in the Windows TPM.

Mitigations and what’s at risk

The GBHackers News coverage says defenders are advised to limit unnecessary access to Windows event logs, review memberships in the Event Log Readers and remote-management groups, and monitor any unusual access to the WebAuthn Operational log.

limit unnecessary access to Windows event logs

GBHackers NewsGBHackers News

It also says Entra ID administrators should prioritize device-bound, hardware-backed passkeys for high-value accounts, require attestation when practical, and avoid using shared user endpoints for privileged identities.

The Cyber Press article adds that Microsoft addressed the Windows logging weakness as CVE-2026-34348 in its July 14, 2026 security updates, and that patched systems truncate the signature component stored in the log to six bytes.

The Hacker News reported that as of August 10, SpecterOps said Entra still uses JSON Web Tokens (JWTs) as WebAuthn challenges rather than pseudorandomly generated nonces and does not appear to bind WebAuthn challenges to session cookies.

Ars Technica framed the broader risk as confusion about whether passkeys are truly safe, while also describing how Pass-ta-key could obtain all passkeys stored in the Google Password Manager app (GPM) for Windows when it’s running on a machine infected with malware.

Story read · 14 outlets · 1 disagreement · 1 fact unevenly covered

Coverage map

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Other

9to5Google
9to5Google

Google Password Manager passkeys could be at risk with new ‘Pass-ta-key’ attack

04 August, 2026

BleepingComputer
BleepingComputer

New Pass-ta-key attacks let malware hijack Google-synced passkeys

03 August, 2026

Cyber Press
Cyber Press

Pass-the-Passkey Attack Bypasses Phishing-Resistant MFA and Impersonates Privileged Users

11 August, 2026

GBHackers News
GBHackers News

Pass-the-Passkey Attack Exploits Windows and Entra ID to Bypass MFA

11 August, 2026

HotHardware
HotHardware

Google Synced Passkeys Can Be Hijacked By Malware In New Attack

04 August, 2026

Infosertec
Infosertec

Google Passkeys, vulnerable to the “Pass-ta-key” attack

04 August, 2026

LinkedIn
LinkedIn

New Passkey Attacks Expose Private Keys and Bypass Phishing-Resistant MFA Without Breaking Encryption

10 August, 2026

Malwarebytes
Malwarebytes

Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks

05 August, 2026

Portal Innova
Portal Innova

Unit 42: 3 attacks steal Google passkeys without interaction

05 August, 2026

RedesZone
RedesZone

Researchers detect attacks that allow stealing synchronized keys from Google’s password manager

04 August, 2026

Unit 42
Unit 42

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

03 August, 2026

Western Mainstream

Ars Technica
Ars Technica

New Pass-ta-key attack reveals all the things we didn’t know about passkeys

11 August, 2026

The Hacker News
The Hacker News

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

11 August, 2026

Asian

GIGAZINE
GIGAZINE

A security firm has reported a 'Pass-ta-key' attack method that exploits a vulnerability in Google Password Manager to bypass passkey authentication.

05 August, 2026

NewsCord Digest

Get every Technology and Science story like this one, in one email

Daily or weekly, only the topics you follow, each with the difference our analysis found across the outlets covering it.

Set up your digest

More on Technology and Science