← Back to Feed

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

August 3, 2026 · Unit 42 · Severity: MEDIUM

This article explores how gaps in passkey implementation can undermine security when relying parties fail to validate the User Verified flag. This oversight reduces multi-factor authentication to a single factor, creating a novel attack surface in passwordless authentication.

Key Takeaways

  • Passkey implementation gaps can allow bypassing user verification, reducing MFA strength.
  • Relying parties failing to validate the User Verified flag undermines passwordless security.
  • Attackers can exploit these gaps to downgrade MFA to a single factor.
☕ Buy a Coffee