🟠 High  |  Source: The Hacker News


Unit 42 researchers have identified three attack techniques — collectively dubbed ‘Pass-ta-key’ — that allow malware running with standard user privileges on Windows to silently authenticate to passkey-protected accounts via Google Password Manager, bypassing biometric or PIN prompts entirely. The attacks target Chrome’s cloud authenticator and, in the most severe variant, compromise a master key that could expose multiple accounts. This is significant because passkeys are widely promoted as a phishing-resistant replacement for passwords, and this research demonstrates that local malware can undermine that protection without any user interaction.

Security Architect’s Take: Organisations relying on Google Password Manager for passkey storage should treat endpoint compromise as a full account compromise event — enforce endpoint detection and response (EDR) tooling capable of detecting credential-harvesting behaviour at the Chrome process level, and consider mandating hardware security keys (FIDO2 roaming authenticators) rather than platform authenticators for privileged or sensitive accounts.

Original advisory: Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts