logo

Pass the Passkey

ID: 563ad30c-ad7b-47cf-ba56-6f02f2b5ce0e

STIX ID: report--563ad30c-ad7b-47cf-ba56-6f02f2b5ce0e

Threat Score

72/100

Uploaded: 2026-08-21

Published Date: 2026-08-21

Last Modified Date: 2026-08-21

Created by: OpenCTI

TLP:CLEAR
ADMIRALTY:A1
...
...
Executive summary: This white paper analyzes three practically exploitable WebAuthn/Passkey vulnerabilities in Windows 11 and Microsoft Entra ID, detailing how WebAuthn assertions can be replayed, forged, or hijacked via local event logs, OS prompts, and attacker-controlled tooling; it presents multiple attack techniques (replay, circuit breaker, phishing, prompt flooding, UI spoofing, and remote-relay), describes open-source tooling (Passkey Injector, SharpPasskeys, DSInternals UI) and OPSEC considerations, and offers mitigations and timelines. It is a threat intelligence research document rather than a report of a single incident.