← Back to Feed
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
August 3, 2026 · Unit 42 · Severity: MEDIUM
This article explores how gaps in passkey implementation can undermine security when relying parties fail to validate the User Verified flag. This oversight reduces multi-factor authentication to a single factor, creating a novel attack surface in passwordless authentication.
Key Takeaways
- Passkey implementation gaps can allow bypassing user verification, reducing MFA strength.
- Relying parties failing to validate the User Verified flag undermines passwordless security.
- Attackers can exploit these gaps to downgrade MFA to a single factor.