SECURITYBLEEPING COMPUTER
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers discovered three attacks allowing malware on compromised Windows devices to exploit Google Password Manager's synced passkeys, enabling account takeovers and bypassing user verification to extract private keys.
Mentioned
Related Signal
Adjacent reporting
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
- Hackers Used AI to Build a Zero-Day Exploit That Bypasses Two-Factor Authentication: Google
- Stop using passwords online, says GCHQ: New passkeys 'remove entire classes of attacks' from hackers
- The New Phishing Click: How OAuth Consent Bypasses MFA