Home / Aug 05, 2026 / Story
0
#4 BleepingComputer general August 03, 2026 at 23:58 UTC

New Pass-ta-key attacks let malware hijack Google-synced passkeys

By Lawrence Abrams

AI Summary

Researchers disclosed three 'Pass-ta-key' attack techniques allowing malware on compromised Windows devices to abuse Google Password Manager's passkey sync to hijack accounts, bypass user verification, and extract passkey private keys. The findings challenge the assumption that FIDO2 passkeys are phishing-resistant by default when device-level compromise is already achieved. Security practitioners should treat passkey implementations as dependent on underlying device security posture.

Relevance score: 88.0/100

# More from August 05