It's no secret that passwords are particularly vulnerable to phishing and brute force attacks. This has led to the widespread adoption of passkeys, an authentication method that leverages cryptographic key pairs and allows users to log in to services with biometrics or a hardware key.

According to FIDO, over 15 billion accounts have enabled passkey protection, with 69% of users worldwide having enabled it on at least one account. The promise of passkeys is simple – eliminate passwords, eliminate vulnerabilities.
However, SquareX researchers Shourya Pratap Singh, Daniel Seetoh, and Jonathan Lin revealed a major vulnerability in passkeys at DEF CON 33. The vulnerability puts important accounts of banks, marketplaces, and SaaS applications for businesses at risk .
See also: Beware! New Sni5Gect attack targets 5G network
How do passkeys work?
Passkeys work using a cryptographic key pair. The private key is stored device user's, while the public key is stored on the website's server. When logging in, the user authenticates locally with their biometrics, local hardware key, or a PIN.
The website then verifies this signature with the corresponding public key to grant access. This design enhances security by linking authentication to a pre-registered device and website. This eliminates the risks associated with stolen, reused, or weak passwords.

All communication between the server and the user’s device is transmitted through the browser. This means that passkeys operate under the assumption that the browser is “trusted.” However, SquareX researchers have shown that through relatively simple scripts and extensions browser, attackers can intercept and spoof the passkey registration process, gaining access to accounts without the actual device or biometrics.
See also: Warning: Hackers Attack FreePBX Servers
Even with registered passkeys, attackers can cause passkey login to fail, forcing users to -enter retheir passkeys in an attacker-controlled environment.
“ Passkeys are a highly trusted form of authentication, so when users see a prompt for biometric verification, they assume it’s secure ,” SquareX says . “ What they don’t know is that attackers can easily spoof passkey registrations and authentication by intercepting the passkey workflow in the browser. This puts nearly every enterprise and consumer application at risk, including critical banking and data storage apps .”
Unfortunately, traditional security tools like EDR and SASE/SSE lack the necessary visibility into the browser to detect passkey exploits. From the user’s perspective, the attack is identical to a legitimate passkey workflow. In other words, there is no visual indicator or network signal that can verify the legitimacy of the authentication service and/or request. Thus, the only way to prevent the exploit is to monitor and block any malicious scripts and extensions directly in the browser.

With over 80% of enterprise data now residing in SaaS applications, passkeys are emerging as the dominant authentication method for accessing these platforms.
See also: CISA: Guide to protecting networks from Chinese hackers Salt Typhoon
SquareX's research showed that browsers represent the weak point in passkey security and provide the breeding ground for multiple attack vectors that malicious actors can leverage to exploit passkeys.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
As passkeys become established as the gold standard for authentication, businesses need to ensure that strong security measures to protect the environment where users and passkeys operate – the browser.
