Google Synced Passkeys Can Be Hijacked By Malware In New Attack
Cybersecurity researchers at Palo Alto Networks' Unit 42 have uncovered three novel post-compromise attack vectors that allow local malware on Windows PCs to quietly hijack Google-synced passkeys, bypassing biometric checks and PIN prompts.
Dubbed Pass-TA-Key, Silver Pass-TA-Key, and Golden Pass-TA-Key, the techniques target the Google Password Manager in Chrome on Windows machines equipped with a Trusted Platform Module (TPM). Now, passkeys are widely considered the current gold standard for passwordless security because they rely on public-key cryptography to prevent phishing and credential theft. However, these attacks do not crack the cryptographic mathematics. Instead, they exploit how Chrome manages device trust, stores credential metadata, and handles cloud re-enrollment.
The exploitation process starts on an infected endpoint. Chrome saves synchronized credential metadata inside an unencrypted local LevelDB database, giving unprivileged malware a clean index of every service where the victim uses passkey authentication.
In the basic Pass-TA-Key attack, malware extracts Chrome's TPM-backed...
Copyright of this story solely belongs to hothardware.com. To see the full text click HERE