Technology News

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Unit 42 has uncovered that malware can log into Google Password Manager accounts without biometric or PIN verification, exploiting three distinct attack paths.

Unit 42 has revealed that malware running as a standard user on a Windows machine can log into a victim’s Google Password Manager accounts without any biometric or PIN prompt appearing on the victim’s screen.

The attack relies on three distinct paths, all targeting Chrome’s cloud‑based authenticator that Google calls Pass-ta-key.

The first path, dubbed Pass-ta-key, exploits the master key that unlocks all stored passwords.

Silver Pass-ta-key uses an intermediate key that is less protected than the master key but still grants full account access.

Golden Pass-ta-key is the most powerful of the three, allowing the attacker to bypass all local authentication measures and directly control the account.

Because the malware operates with the same privileges as an ordinary user, it can avoid raising alarms on the victim’s system.

The findings highlight that even accounts protected by passkeys—supposedly the next generation of passwords—remain vulnerable if the underlying keys are not adequately isolated.

Google has confirmed awareness of the issue and is working on a patch that will strengthen the isolation of the master key.

Security experts advise users to keep their operating systems updated, enable two‑factor authentication where possible, and monitor account activity for unexpected sign‑ins.

The discovery underscores the importance of continuous vigilance and layered defense when adopting new authentication methods.

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Unit 42 has revealed that malware running as a standard user on a Window…

Unit 42 has revealed that malware running as a standard user on a Window…

Unit 42 has revealed that malware running as a standard user on a Windows machine can log into a victim’s Google Password Manager accounts without any biometric or PIN prompt appearing on the victim’s screen.

The attack relies on three distinct paths, all targeting Chrome’s cloud‑based authenticator that Google calls Pass-ta-key.

The first path, dubbed Pass-ta-key, exploits the master key that unlocks…

The first path, dubbed Pass-ta-key, exploits the master key that unlocks…

The first path, dubbed Pass-ta-key, exploits the master key that unlocks all stored passwords.

Silver Pass-ta-key uses an intermediate key that is less protected than the master key but still grants full account access.

Golden Pass-ta-key is the most powerful of the three, allowing the attac…

Golden Pass-ta-key is the most powerful of the three, allowing the attac…

Golden Pass-ta-key is the most powerful of the three, allowing the attacker to bypass all local authentication measures and directly control the account.

Because the malware operates with the same privileges as an ordinary user, it can avoid raising alarms on the victim’s system.

The findings highlight that even accounts protected by passkeys—supposed…

The findings highlight that even accounts protected by passkeys—supposed…

The findings highlight that even accounts protected by passkeys—supposedly the next generation of passwords—remain vulnerable if the underlying keys are not adequately isolated.

Google has confirmed awareness of the issue and is working on a patch that will strengthen the isolation of the master key.

Security experts advise users to keep their operating systems updated, e…

Security experts advise users to keep their operating systems updated, e…

Security experts advise users to keep their operating systems updated, enable two‑factor authentication where possible, and monitor account activity for unexpected sign‑ins.

The discovery underscores the importance of continuous vigilance and layered defense when adopting new authentication methods.