Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Summary

Researchers have identified three attack paths, collectively named Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, that could allow malware on a Windows machine to hijack accounts protected by Google Password Manager's passkey feature. These attacks bypass the need for user authentication like fingerprints or PINs, with the strongest targeting the master key.

IFF Assessment

FOE

The article describes novel attack methods that could compromise user accounts protected by passkeys, posing a significant risk to defenders.

Defender Context

Defenders should be aware of potential malware targeting the passkey implementation within Google Password Manager. This highlights the ongoing need for robust endpoint security solutions to detect and prevent malware, as well as vigilance regarding credential management practices. Users should ensure their systems are up-to-date and employ multi-factor authentication where available.

Read Full Story →