← Back to Feed
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
August 3, 2026 · Unit 42 · Severity: MEDIUM
This article from Unit 42 explores a novel attack surface called 'Pass the Passkey' in passwordless authentication. It highlights how implementation gaps, specifically when relying parties fail to validate the User Verified flag, can reduce multi-factor authentication to a single factor, compromising security.
Key Takeaways
- Passkey implementation gaps can reduce MFA to a single factor security.
- Relying parties fail to validate the User Verified flag in passkey authentication.
- This undermines passwordless authentication by enabling pass-the-passkey attacks.