CYBERSECURITYTRACKER
TRACKING6,902 stories in this site build1,444 vulnerability news stories in this site build
Permanent story citation

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3749

As cited

Copy frozen at (site build).

vulnerabilities

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Unit 42 researchers identified three attack paths against Chrome's Google Password Manager that allow malware running with ordinary user privileges to sign into passkey-protected accounts without user interaction or biometric verification. The attacks, ranging from Silver Pass-ta-key to Golden Pass-ta-key, exploit the cloud authenticator's key management to bypass passkey protections.

Why it matters: Organizations and individuals using Chrome's Google Password Manager for passkey authentication face account takeover risk if their Windows machines are compromised by malware; security teams should review passkey implementation security and consider additional controls around credential access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Unit 42 researchers identified three attack paths against Chrome's Google Password Manager that allow malware running with ordinary user privileges to sign into passkey-protected accounts without user interaction or biometric verification. The attacks, ranging from Silver Pass-ta-key to Golden Pass-ta-key, exploit the cloud authenticator's key management to bypass passkey protections.

Why it matters: Organizations and individuals using Chrome's Google Password Manager for passkey authentication face account takeover risk if their Windows machines are compromised by malware; security teams should review passkey implementation security and consider additional controls around credential access.

VendorsGoogleMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary