By Interestana AI Editorial — AI-drafted, human-overseen. How we report
New Pass-ta-key Attacks Hijack Google-Synced Passkeys
Security researchers have identified three novel "Pass-ta-key" attacks that enable malware, already present on compromised Windows devices, to exploit Google Password Manager's synced passkeys. These attacks permit threat actors to seize control of user accounts, circumvent multi-factor authentication, and exfiltrate the private keys associated with passkeys. The vulnerabilities leverage the synchronization mechanism of Google Password Manager, which stores and syncs passkey credentials across a user's devices. By gaining access to a compromised Windows machine, attackers can target the local storage of these synced passkeys. The research, detailed in a recent security advisory, highlights a significant new threat vector for passkey-protected accounts, which are increasingly adopted as a more secure alternative to traditional passwords. Passkeys are designed to be phishing-resistant and are generated as a pair of cryptographic keys: a public key stored by the service provider and a private key stored securely on the user's device. The synchronization feature, intended for user convenience, inadvertently creates a potential point of compromise if the local device is already infected with malware. The attackers can then access the passkey private keys stored on the Windows machine. This allows them to impersonate the legitimate user on any service that uses the synced passkey. The implications are far-reaching, as many platforms, including Google, Apple, and Microsoft, are encouraging users to migrate to passkeys for enhanced security. The discovery underscores the importance of robust endpoint security measures, even when employing advanced authentication methods like passkeys. Organizations and users alike must remain vigilant against malware and ensure their devices are protected against initial compromise. The researchers have not yet disclosed the specific technical details of the attacks or the affected versions of Google Password Manager, but they have indicated that the findings will be presented at the upcoming USENIX Security Symposium. This development poses a challenge to the broader adoption of passkeys, as it demonstrates that even seemingly secure authentication methods can be vulnerable if the underlying device ecosystem is compromised. The attacks specifically target the passkey private keys stored locally on Windows devices that are synced with Google Password Manager. This means that if a user has passkeys for various services (e.g., social media, banking, email) synced through their Google account, malware on a compromised Windows machine could potentially gain access to all of them. The security community is now awaiting further details and potential mitigation strategies from Google and other affected parties to address this emerging threat. The success of these attacks relies on the malware already having achieved a privileged position on the Windows device, allowing it to read sensitive data from the operating system or user profiles where the passkey data is stored. This highlights the critical need for comprehensive cybersecurity practices, including regular software updates, antivirus protection, and user education on safe browsing habits, to prevent the initial compromise that enables such sophisticated attacks.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.