Follow ZDNET: Add us as a preferred source on Google. At this year's DEF CON conference in Las Vegas, white hat security researcher Marek Tóth demonstrated how threat actors could use a clickjack attack to surreptitiously trigger and hijack a passkey-based authentication ceremony. In the big picture, this is a story about how password managers could be tricked into divulging login information -- either traditional credentials such as user IDs and passwords or credential-like artifacts associated with passkeys -- to threat actors. Also: 10 passkey survival tips: Prepare for your passwordless future now Are password managers to blame? Tóth -- the researcher who discovered the exploit -- suggests that they are, but the answer is more complicated. Fully locking down any automated process is invariably the result of security in layers. Across the grand majority of use cases where digital security matters, there's almost never a single silver bullet that wards off hackers. Depending on the layers of technology that combine to complete a workflow (for example, logging into a website), responsibility for the security of that process is shared by the parties that control each of those layers. Yes, the password managers are one layer in stopping the exploit. But website operators and end-users -- the parties in control of the other layers -- must trade too much security for convenience in order for the exploit to work. Pointing fingers is useless. All parties at every layer must take a...
Your passkeys could be vulnerable to attack, and everyone - including you - must act
ZDNet
·David Berlind
·Published Sep 20, 2025
·Updated
Affected Software
1 affected component
Various Password Manager
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses vulnerabilities in passkey-based authentication systems and the potential for clickjack attacks.
2
What security implications are discussed?
The security implications include the risk of unauthorized access to accounts due to clickjack attacks on passkey authentication.
3
What products or software are affected?
Various password manager software that utilize passkey authentication are at risk of these vulnerabilities.
4
Who demonstrated the vulnerabilities at DEF CON?
White hat security researcher Marek Tóth demonstrated the passkey vulnerabilities at the DEF CON conference.
5
What action should users take regarding their passkeys?
Users must take proactive measures to secure their passkeys to prevent exploitation by threat actors.