Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
By [email protected] (The Hacker News)
AI Summary
Unit 42 researchers detailed three attack paths — dubbed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — against Chrome's Google Password Manager cloud authenticator, allowing malware running as a standard Windows user to silently sign into passkey-protected accounts without triggering any fingerprint or PIN prompts. The Golden Pass-ta-key variant can extract the passkey private key itself using the master key. This fundamentally undermines the security guarantees of passkeys when an endpoint is compromised, requiring practitioners to reconsider endpoint-trust assumptions in passkey deployments.
Relevance score: 88.0/100
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →