Passkeys in Google Chrome Are Open to Attack, With One Big Caveat

Security researchers at Palo Alto Networks have discovered a vulnerability in Google Chrome that allows malware to bypass passkey security. By reading plaintext data from the Google Password Manager, attackers can manipulate the cloud authenticator to falsify authentication.
Why it matters
This highlights a critical security risk for users relying on passkeys, demonstrating that even advanced authentication methods are vulnerable if the underlying device is compromised.
<p>Researchers found a way to bypass Chrome's passkey security and steal the codes directly from the browser of a PC infected by malware.</p><p>The big reason <a href="https://www.pcmag.com/explainers/still-using-passwords-its-time-to-upgrade-to-passkeys" target="_self">passkeys</a> are safer is that they can't be stolen, copied, or guessed. There's no way to social engineer a passkey that can then be used remotely. But if the device the passkey is stored on is compromised, that can be a real problem. In this case, researchers from Palo Alto Networks' <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" title="(Opens in a new tab)">Unit 42</a> were able to read enough plaintext data from <a href="https://www.pcmag.com/how-to/how-to-master-google-password-manager" target="_self">Google's Password Manager</a> to manipulate the cloud authenticator and access whatever the passkey protected.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in