Malware Can Hijack Passkey-Protected Accounts via Google Password Manager
Researchers have detailed three attack paths, dubbed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, that could allow malware on a Windows machine to silently sign into passkey-protected accounts managed by Google Password Manager in Chrome. The attacks target how Chrome stores device keys and re-enrolls devices, potentially allowing for reusable access from an attacker's environment after an initial endpoint compromise.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.