Researchers have uncovered new attack vectors that can undermine passkey authentication, challenging the idea that passwordless automatically means attack-proof. The attacks focus on weaknesses around the authentication flow and implementation, rather than breaking the underlying cryptography. Manipulation of WebAuthn processes, fallback mechanisms and compromised environments can potentially allow attackers to bypass or weaken passkey protection. […]

