As cited
Copy frozen at (site build).
vulnerabilities
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Unit 42 researchers identified three attack paths against Chrome's Google Password Manager that allow malware running with ordinary user privileges to sign into passkey-protected accounts without user interaction or biometric verification. The attacks, ranging from Silver Pass-ta-key to Golden Pass-ta-key, exploit the cloud authenticator's key management to bypass passkey protections.
Why it matters: Organizations and individuals using Chrome's Google Password Manager for passkey authentication face account takeover risk if their Windows machines are compromised by malware; security teams should review passkey implementation security and consider additional controls around credential access.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Unit 42 researchers identified three attack paths against Chrome's Google Password Manager that allow malware running with ordinary user privileges to sign into passkey-protected accounts without user interaction or biometric verification. The attacks, ranging from Silver Pass-ta-key to Golden Pass-ta-key, exploit the cloud authenticator's key management to bypass passkey protections.
Why it matters: Organizations and individuals using Chrome's Google Password Manager for passkey authentication face account takeover risk if their Windows machines are compromised by malware; security teams should review passkey implementation security and consider additional controls around credential access.
- Source published
- First seen by Cybersecurity Tracker