Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
ID: 316bcd25-0afb-573d-b9da-3ba1884c910e
STIX ID: report--316bcd25-0afb-573d-b9da-3ba1884c910e
Feed Name: Malwarebytes Blog
Researchers have demonstrated that malware can abuse Google Password Manager's passkey synchronization to hijack passkey-protected accounts. They outline three attacks—"Pass‑ta‑key" (malware requests valid passkey assertions without biometric/PIN prompts), "Silver Pass‑ta‑key" (abusing device re-enrollment to register attacker-controlled verification keys), and "Golden Pass‑ta‑key" (extracting Google’s master encryption key to decrypt all synced passkeys). The report urges server-side validation of genuine user verification, stronger device registration/recovery controls, and continued anti-malware hygiene for users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
