New malware can extract passkeys from Google Password Manager
Security researchers from Palo Alto Networks' Unit 42 discovered three attacks called Pass-ta-key that allow malware on Windows devices to abuse synced passkeys from Google Password Manager and take over user accounts. The attacks require malware to already be running on the computer and exploit weaknesses in how Chrome and Google's cloud authenticator handle device trust, onboarding, recovery, and synced credentials.
Malware can access all your passwords in Google Password Manager and breach most of your services. If Google remains silent on this, I recommend switching to Bitwarden or a similar solution and deleting passwords from Google Password Manager.
What are passkeys and why are they considered more secure than passwords?
Passkeys are a passwordless authentication method based on cryptographic keys stored on a user's device used to sign in to online accounts. Unlike passwords, passkeys cannot be guessed, reused, or easily stolen through phishing, and they enable authentication using a PIN or biometrics such as fingerprints or facial recognition.
How do the three Pass-ta-key attack variants differ from each other?
The basic Pass-ta-key allows unprivileged malware to impersonate a trusted device and obtain an authentication response; Silver Pass-ta-key enables an attacker to register their own user-verification key with Google's authenticator; Golden Pass-ta-key is the most severe and allows extraction of the master key that encrypts all synced passkeys from Google Password Manager.
What mitigations do security researchers recommend?
Researchers recommend that websites require and properly validate user verification, credential managers should validate newly registered device keys and harden recovery processes, and system should prevent master keys from becoming accessible in browser memory.
- Android 17 implements ECH to hide website visits from network providers — thehackernews.com 81 % match
- WindRelay Android malware for NFC payment fraud expanding to Czech Republic — thehackernews.com 77 % match
- Kimsuky builds offline AI stack to enhance phishing and automate malware development — thehackernews.com 77 % match