Report: Passkey security issues could allow account takeover
Summary
A Palo Alto Networks report found that attackers can take over accounts protected by passkeys (a password alternative using cryptography) if they first get malware onto a user's device, exploiting weaknesses in account recovery and onboarding processes rather than breaking passkey encryption itself. The attacks, called Pass-ta-key variants, can extract passkey private keys (the secret codes that unlock accounts) or trick authentication systems into granting access without the user's knowledge. Security experts stress the issue stems from how passkeys are implemented in real systems, not flaws in passkey technology itself.
Solution / Mitigation
According to consultant Brian Levine in the source: "On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response." Frank Dickson adds: "Stop treating verification as optional. Flip it to required, check it server side."
Classification
Original source: https://www.csoonline.com/article/4205751/report-passkey-security-issues-could-allow-account-takeover.html
First tracked: August 5, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%