Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Summary
Researchers have identified three attack paths, collectively named Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, that could allow malware on a Windows machine to hijack accounts protected by Google Password Manager's passkey feature. These attacks bypass the need for user authentication like fingerprints or PINs, with the strongest targeting the master key.
IFF Assessment
The article describes novel attack methods that could compromise user accounts protected by passkeys, posing a significant risk to defenders.
Defender Context
Defenders should be aware of potential malware targeting the passkey implementation within Google Password Manager. This highlights the ongoing need for robust endpoint security solutions to detect and prevent malware, as well as vigilance regarding credential management practices. Users should ensure their systems are up-to-date and employ multi-factor authentication where available.