Microsoft has addressed a critical Windows security flaw that previously exposed WebAuthn signatures in event logs, potentially enabling MFA bypass via privileged impersonation. Researchers highlight ongoing risks from endpoint passkey exposures and malicious activity within compromised sessions.
Microsoft’s July 2026 Windows updates appear to have closed one of the more practical replay paths researchers had found for bypassing phishing-resistant multifactor authentication. SpecterOps said Windows could expose YubiKey and other WebAuthn signatures in readable event-log data, which, when paired with weaknesses in Microsoft Entra ID challenge validation, could let an attacker impersonate a privileged user without defeating the underlying cryptography. Microsoft has now fixed the Windows information-disclosure flaw, and SpecterOps says the full Windows-to-Entra chain is no longer viable after the patch.
The issue, tracked as CVE-2026-34348, affected the Windows Event Logging Service and could allow an authorised attacker to disclose information over a network. Microsoft’s Security Response Center says administrators should apply the July 2026 Windows and Windows Server updates, then check for privileged sign-ins and other unusual authentication activity. The company has not shared much technical detail about any separate Entra-side changes.
A separate line of research has shown that synced passkeys can also be exposed at the endpoint. Unit 42 said Chrome on Windows temporarily keeps Google Password Manager’s 32-byte Security Domain Secret in process memory during passkey re-registration. If malware is already on the machine, that secret can be used in what the researchers called a “Golden Pass-ta-key” attack to recover private keys for synced passkeys. Google has removed the secret from Chrome’s device logs, but the researchers said it cannot currently be rotated or revoked, which makes the risk longer lived than a one-off captured login assertion.
Another finding, from security researcher Dirk-jan Mollema, shows that a low-privilege process inside a compromised Windows session can call a Windows Hello for Business key without forcing a new PIN or biometric check. The TPM-backed key itself remains non-exportable, but malware can still use it to produce a valid FIDO2 assertion for Microsoft Entra ID. Taken together, the research does not show that FIDO2 is broken remotely. It does show that once an attacker has a foothold on the device, browser memory, signed assertions, synced-key recovery and unattended credential use can all weaken strong authentication in practice.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





