#4
BleepingComputer
general
August 03, 2026 at 23:58 UTC
New Pass-ta-key attacks let malware hijack Google-synced passkeys
By Lawrence Abrams
AI Summary
Researchers disclosed three 'Pass-ta-key' attack techniques allowing malware on compromised Windows devices to abuse Google Password Manager's passkey sync to hijack accounts, bypass user verification, and extract passkey private keys. The findings challenge the assumption that FIDO2 passkeys are phishing-resistant by default when device-level compromise is already achieved. Security practitioners should treat passkey implementations as dependent on underlying device security posture.
Relevance score: 88.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →