Home / Technology

Photo of office team, robotics warehouse, solar panels
Image: Wikipedia
Technology

Google's Passkey Ecosystem Vulnerable to Novel Attacks

WireByte Staff · August 5, 2026

Researchers at Palo Alto Networks have discovered vulnerabilities in Google's passkey ecosystem, allowing attackers to bypass user verification and extract synced passkey private keys. The attacks exploit weaknesses in onboarding, recovery, and device trust workflows. The findings highlight the need for defenders to prepare for new attack surfaces as passkeys become widely adopted.

Key points

  • Palo Alto Networks researchers discovered vulnerabilities in Google's passkey ecosystem, allowing attackers to bypass user verification and extract synced passkey private keys.
  • The attacks exploit weaknesses in onboarding, recovery, and device trust workflows within Google's Cloud Authenticator.
  • The findings highlight the need for defenders to prepare for new attack surfaces as passkeys become widely adopted.
  • Passkeys replace passwords and traditional multi-factor authentication (MFA) with public-key cryptography, decreasing entire classes of attacks.
  • The researchers recommend that defenders prepare for a new generation of attacks as passkeys scale to billions of accounts.

Google's Passkey Ecosystem Vulnerable to Novel Attacks

Researchers at Palo Alto Networks have discovered vulnerabilities in Google's passkey ecosystem, allowing attackers to bypass user verification and extract synced passkey private keys. The attacks exploit weaknesses in onboarding, recovery, and device trust workflows within Google's Cloud Authenticator.

The findings highlight the need for defenders to prepare for new attack surfaces as passkeys become widely adopted. Passkeys replace passwords and traditional multi-factor authentication (MFA) with public-key cryptography, decreasing entire classes of attacks. However, the researchers recommend that defenders prepare for a new generation of attacks as passkeys scale to billions of accounts.

This is the third part in a series examining passkey adoption from a security perspective. The researchers aim to raise awareness about the potential risks and vulnerabilities associated with passkey adoption, and to encourage defenders to prepare for the new threats that may arise.

Sources

WireByte Staff — Editorial Team

The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.