← Back to Feed

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

August 3, 2026 · Unit 42 · Severity: MEDIUM

This article from Unit 42 explores a novel attack surface called 'Pass the Passkey' in passwordless authentication. It highlights how implementation gaps, specifically when relying parties fail to validate the User Verified flag, can reduce multi-factor authentication to a single factor, compromising security.

Key Takeaways

  • Passkey implementation gaps can reduce MFA to a single factor security.
  • Relying parties fail to validate the User Verified flag in passkey authentication.
  • This undermines passwordless authentication by enabling pass-the-passkey attacks.
☕ Buy a Coffee