Google Password Manager Attacks Hijack Synced Passkeys

Security researchers have identified three new attack vectors that could allow malware to hijack passkeys synced via Google Password Manager. These vulnerabilities target various stages of the authentication process, potentially compromising user accounts on Windows devices.
Why it matters
The discovery highlights significant security risks in passwordless authentication systems, necessitating urgent updates to device trust and verification protocols.
Security researchers have uncovered three new attacks that could let malware hijack Google-synced passkeys and take over online accounts from compromised Windows devices.
The techniques target Google Password Manager in Chrome and abuse weaknesses in device trust, user verification, re-registration, credential recovery, and passkey synchronization.
Depending on the technique, attackers could bypass verification, authenticate from another system, or recover the private keys protecting synced credentials.
Unit 42 did not report observing exploitation in the wild, and the available research does not identify affected Chrome versions or confirm whether every attack path has been fully addressed.
Palo Alto Networks Unit 42 named the techniques Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key. Each targets a different part of Google Password Manager’s passwordless authentication system, including device identity, user verification , recovery, and credential synchronization.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in