Researchers found a way to steal passkeys straight out of Chrome's memory

https://www.techspot.com/images2/news/ts3_thumbs/2025/06/2025-06-20-ts3_thumbs-3bb.jpg

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

In brief: Tech companies are rapidly replacing passwords with passkeys because they are easier to use and more secure. However, researchers recently demonstrated that passkeys are not foolproof. The way Google's authenticator stores passkeys in Chrome allows malware to spoof passkey authentication and hijack accounts in multiple ways.

Researchers at Unit 42 recently detailed three methods by which malware on a PC can read passkey data stored in Google Chrome. The most severe method completely compromises the victim's Google passkey vault, granting attackers remote access to every account that relies on passkeys.

Google, Microsoft, Apple, and many other companies are turning away from passwords, largely because users keep settingones like "1234." Passkeys, stored on a user's device and decrypted on cloud services via PINs and biometrics, are even considered safer than password...

Copyright of this story solely belongs to techspot.com. To see the full text click HERE

Read more