Interestana
Home/News/Malware Can Hijack Passkey-Protected Google Accounts
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Malware Can Hijack Passkey-Protected Google Accounts

Malware Can Hijack Passkey-Protected Google Accounts

Malware operating with standard user privileges on a Windows system can now gain unauthorized access to passkey-protected accounts, bypassing essential security measures such as fingerprint scans or PIN entry. This vulnerability allows attackers to sign into accounts without any visible prompts or interactions from the legitimate user. Palo Alto Networks' Unit 42 cybersecurity team has identified and detailed three distinct attack vectors targeting Chrome's cloud-based Google Password Manager, which facilitates passkey authentication. These attack paths have been collectively named "Pass-ta-key," "Silver Pass-ta-key," and "Golden Pass-ta-key." The most potent of these exploits, the "Golden Pass-ta-key" attack, specifically targets the master key used to encrypt and protect the stored credentials within the Google Password Manager. This master key is crucial for the integrity of the password manager's security. The researchers demonstrated that by compromising this master key, an attacker could effectively gain control over all passkeys stored and managed by the Google Password Manager on the affected device. The attack leverages the way Chrome stores and encrypts sensitive authentication data locally. While passkeys are designed to be more secure than traditional passwords by using cryptographic key pairs and often requiring biometric authentication, this new class of malware exploits vulnerabilities in the local storage and management of these keys on Windows machines. The Unit 42 report highlights that the malware can exfiltrate the encrypted passkey data and then decrypt it locally, or in some cases, directly manipulate the authentication process. This discovery raises significant concerns for users who rely on Google Password Manager for securing their online accounts, particularly those transitioning to passkey-based authentication for enhanced security. The implications extend to any service that integrates with Google Password Manager for passkey management. The researchers have not disclosed specific details about the malware's propagation methods or its prevalence in the wild, but the potential for widespread compromise is significant given the popularity of Google Chrome and its integrated password management features. The findings underscore the ongoing arms race between cybersecurity researchers and malicious actors, emphasizing the need for continuous vigilance and robust security practices across all layers of digital infrastructure, including local device security and cloud-based services. Users are advised to maintain up-to-date operating systems and security software, and to be cautious of phishing attempts or suspicious downloads that could lead to malware infection. The effectiveness of these attacks relies on the malware already being present on the victim's machine and possessing the necessary privileges to access the Chrome user profile data. The research team's work provides critical insights into the evolving threat landscape surrounding passkey technology and its implementation.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next