SECURITYMALWAREBYTES LABS
Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
Researchers discovered malware can steal Google synchronized passkeys through Google Password Manager, exploiting vulnerabilities in the software despite passkeys being based on public-key cryptography. The 'Pass-ta-key' attacks include scenarios where malware creates unauthorized logins, re-enrolls devices, or decrypts passkeys using a master encryption key.
Mentioned
Related Signal
Adjacent reporting
- New Pass-ta-key attacks let malware hijack Google-synced passkeys
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
- Threat hunters find Google API keys still usable 23 minutes after deletion
- Hackers Used AI to Build a Zero-Day Exploit That Bypasses Two-Factor Authentication: Google