VulnerabilitiesJul 22, 2026
Flaws in Passkey Implementation Show Old Attacks Still Work
Microsoft passkey implementation flaws allow old attacks to impersonate privileged users.
Vendor Watch
Run Microsoft?
Get an email when a reviewed story names Microsoft, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Researchers discovered critical vulnerabilities in Microsoft's passkey implementation that could enable attackers to impersonate privileged users. These flaws leverage older attack techniques, demonstrating that established security weaknesses persist even with newer authentication methods. The findings are set to be presented at Black Hat USA.
Entities
Microsoft (vendor)