Attack Paths Circumvent Passkeys' Phishing Resistance
11 October 2026
WebAuthn passkeys are marketed as phishing-resistant, with authentication cryptographically bound to the registered origin or relying party (RP) ID. But recent research and vendor reports reveal attack paths, including replayed assertions, spoofed prompts, and vulnerabilities in synchronized credentials.
The Claimed Resistance
The WebAuthn protocol model uses a cryptographic relationship between an authenticated device, an RP, and a user. Since credentials are linked to the RP ID and not simply a URL, an attacker's fake login page or redirect can't capture the assertion.
WebAuthn also guards against assertion replay, a previous MFA weakness. Its specifications require that challenges contain enough entropy to make guessing infeasible. Correct server-side verification provides phishing resistance, origin-binding, and replay resistance to relying parties using WebAuthn.
The Disclosed Vulnerabilities
Despite these protections, recent findings point to specific bypass techniques. One research report claims that WebAuthn's signature-counter anti-cloning check can fail for synchronized credentials. The check may not run under some conditions, allowing an attacker to successfully pass a cloned credential.
Reports also identify a weak link in the Microsoft ecosystem, with findings showing exploits in Windows 11 and Microsoft Entra ID that could allow attackers to impersonate privileged identities by bypassing phishing-resistant MFA. The primary attack chain depended on the OS logging the complete WebAuthn assertion response for passkey events, which could be replayed. Updated systems now truncate assertion signatures, and Microsoft released patches to address the issue.
The Endpoint Exploits
Reports also detail combined endpoint attack paths against synced passkeys. Researchers found that some malware could generate valid assertions and impersonate users, even without biometric verification or administrator rights. One variant targeted the Security Domain Secret (SDS) used to protect synced passkeys on browsers. The SDS, temporarily present in process memory, had no rotation mechanism at the time of disclosure, leading vendors to implement mitigation measures.
The Warning for Security Buyers
The disclosures reveal that fundamental cryptographic protections aren't absolute because users can't be guaranteed flawless configurations across all devices. Another report noted that attackers could hijack the WebAuthn API to overwrite the authentication prompt shown by the system or browser, phishing users in real time. Endpoint vulnerabilities and man-in-the-middle spoofing can expose users to risk before even reaching the cryptographic stage.
Vendors and enterprise buyers should therefore clarify exactly what they mean by "phishing-resistant" and evaluate their exposure to these surrounding attack vectors.
Closing the Gaps
Defenders can turn to known best practices for mitigating these exploits. Correct server-side validation ensures that assertion responses match the expected challenge, relying on unused challenges to catch replayed requests. Origin-binding and verifier-name binding ensure that credentials only work for the intended RP and prevent impersonation. Device compromise remains dangerous, however; endpoint protection and system updates can help mitigate those risks.
In the longer term, these disclosures reflect a consistent issue in the converged space of security models and their real-world implementations. As trust establishes with passkey adoption, we'll continue discovering and fixing surrounding vulnerabilities. Authentication requirements like FIDO registration and biometrics represent significant progress, but organizations must still address all potential attack vectors in their environments.