By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Exploit Google Passkeys Via Malware

Researchers have identified three distinct methods through which malware, already present on a compromised Windows personal computer, can successfully hijack Google-synced passkeys. These exploits allow attackers to bypass user verification steps and extract all private keys stored within the passkey vault. This development poses a significant security concern for passkeys, which were widely promoted as a more secure alternative to traditional passwords.
The vulnerabilities specifically target passkeys that are synced via a Google account. The first method involves the malware accessing the operating system's credential manager, where it can locate and exfiltrate the passkey data. The second technique leverages the Chrome browser's password manager, which can also store passkey information, making it accessible to malicious software. The third identified exploit targets the passkey data stored within the Google Password Manager application itself, allowing for direct extraction of the sensitive keys.
These findings were detailed in a report by researchers at the German cybersecurity firm G DATA. The firm's analysis indicates that once a Windows PC is compromised with a sufficiently privileged piece of malware, the attacker can gain access to the passkey vault without requiring any further interaction from the user. This means that even if a user has enabled multi-factor authentication or other security layers for their Google account, the passkeys themselves can be stolen if the endpoint device is already compromised. The researchers emphasized that these attacks do not require sophisticated techniques, making them accessible to a wider range of threat actors.
Passkeys are designed to replace passwords by using cryptographic key pairs, with one key stored on the user's device and the other on the service provider's server. A user authenticates by proving they possess the private key on their device, typically through biometric authentication (like fingerprint or facial recognition) or a device PIN. Google, along with other major technology companies, has been actively encouraging users to adopt passkeys as part of a broader industry push towards passwordless authentication, aiming to mitigate risks associated with phishing, credential stuffing, and weak password practices. However, the discovery of these passkey syncing vulnerabilities highlights that the security of passkeys is dependent not only on the cryptographic methods but also on the overall security posture of the user's devices and synced accounts. The researchers have not yet disclosed the specific malware or the exact technical details of the exploits, but they have confirmed that the methods are effective against Google-synced passkeys. This research underscores the ongoing challenges in securing digital identities and the need for continuous vigilance against evolving cyber threats, even with the adoption of seemingly more secure authentication technologies.
Original source — read the full reporting at the publisher:
Read on Digital TrendsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.