• News/
  • https://www.zdnet.com/article/your-passkeys-could-be-vulnerable-to-attack-and-everyone-including-you-must-act/

Your passkeys could be vulnerable to attack, and everyone - including you - must act

ZDNet
·
David Berlind
·
Published Sep 20, 2025
·
Updated

Follow ZDNET: Add us as a preferred source on Google. At this year's DEF CON conference in Las Vegas, white hat security researcher Marek Tóth demonstrated how threat actors could use a clickjack attack to surreptitiously trigger and hijack a passkey-based authentication ceremony. In the big picture, this is a story about how password managers could be tricked into divulging login information -- either traditional credentials such as user IDs and passwords or credential-like artifacts associated with passkeys -- to threat actors. Also: 10 passkey survival tips: Prepare for your passwordless future now Are password managers to blame? Tóth -- the researcher who discovered the exploit -- suggests that they are, but the answer is more complicated. Fully locking down any automated process is invariably the result of security in layers. Across the grand majority of use cases where digital security matters, there's almost never a single silver bullet that wards off hackers. Depending on the layers of technology that combine to complete a workflow (for example, logging into a website), responsibility for the security of that process is shared by the parties that control each of those layers. Yes, the password managers are one layer in stopping the exploit. But website operators and end-users -- the parties in control of the other layers -- must trade too much security for convenience in order for the exploit to work. Pointing fingers is useless. All parties at every layer must take a...

Read full article

Affected Software

1 affected component
Various Password Manager
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses vulnerabilities in passkey-based authentication systems and the potential for clickjack attacks.

2

What security implications are discussed?

The security implications include the risk of unauthorized access to accounts due to clickjack attacks on passkey authentication.

3

What products or software are affected?

Various password manager software that utilize passkey authentication are at risk of these vulnerabilities.

4

Who demonstrated the vulnerabilities at DEF CON?

White hat security researcher Marek Tóth demonstrated the passkey vulnerabilities at the DEF CON conference.

5

What action should users take regarding their passkeys?

Users must take proactive measures to secure their passkeys to prevent exploitation by threat actors.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203