A new "Pass-the-Passkey" family of attack techniques showcases how systemic implementation flaws in WebAuthn can compromise passkey security, even when cryptographic private keys remain securely stored within hardware tokens or trusted enclaves This article explores 11 webauthn assertion. . SpecterOps research reveals three core vulnerabilities across the WebAuthn ecosystem and over 20 distinct attack vectors impacting Windows 11, Microsoft Entra ID, web browsers, password managers, and enterprise authentication workflows.

Pass-the-Passkey Bypass Phishing-Resistant MFA WebAuthn Authentication Flow (Image Source: Specterops.io) SpecterOps identified a primary attack chain stemming from Windows 11 logging complete, un-truncated WebAuthn assertion responses generated during passkey authentication events. When privileged cloud administrators authenticate from compromised workstations, attackers can steal logged assertion material without needing to steal private keys.

Pass-the-Passkey Attacks Overview (Image Source: Specterops.io) In a technical whitepaper published by SpecterOps, researchers revealed that Microsoft Entra ID worsened the impact of assertion exfiltration by omitting essential WebAuthn anti-replay checks during server-side validation. Component Vulnerability / Technique Risk & Impact Windows 11 Full WebAuthn assertion logging in Event Viewer Local information disclosure allowing assertion harvesting Microsoft Entra ID Missing challenge-binding and counter checks Enables replay of harvested assertions to bypass MFA Windows Credential UI Window-handle spoofing and API manipulation Facilitates local passkey phishing and prompt fatigue attacks SpecterOps highlights that passkeys remain fundamentally superior to password-based authentication, especially when device-bound hardware tokens are enforced.