Skip to content
The Nexus
SECURITYAug 5 · 11:11 UTCMALWAREBYTES LABS

Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks

Researchers discovered malware can steal Google synchronized passkeys through Google Password Manager, exploiting vulnerabilities in the software despite passkeys being based on public-key cryptography. The 'Pass-ta-key' attacks include scenarios where malware creates unauthorized logins, re-enrolls devices, or decrypts passkeys using a master encryption key.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting