Reported by 4 sources

The short version

  • New attacks allow malware to hijack Google-synced passkeys without requiring user passwords or biometric data.
  • The vulnerability exploits the synchronization process of Google Password Manager, creating a novel attack surface for passwordless authentication.
  • Security experts warn that these flaws undermine the perceived security benefits of passkey technology.

Security researchers have uncovered significant vulnerabilities in the implementation of passkeys within Google’s ecosystem, revealing that malware can hijack synced passkeys without triggering biometric checks or requiring passwords. The discovery highlights a critical weakness in passwordless authentication systems that were designed to enhance user security by eliminating traditional password entry. These flaws pose a serious threat to users who rely on Google Password Manager for storing and syncing their digital credentials across devices.

The vulnerability, described as a novel attack surface, allows malicious software to intercept passkeys during the synchronization process. Unlike previous attacks that targeted stored passwords or required user interaction, this method exploits the underlying mechanisms of how passkeys are managed and transferred between devices. Researchers from Unit 42 detailed the issue in a report titled 'Pass the Passkey,' explaining how attackers can leverage these weaknesses to gain unauthorized access to protected accounts.

News Journal

According to reports from The Hacker News and CyberSecurityNews, the attack does not require the user’s password or fingerprint verification. This bypasses the primary security features that make passkeys appealing: the elimination of shared secrets and the reliance on local biometric authentication. Instead, malware installed on a compromised device can extract the synced passkey data directly from Google Password Manager, effectively neutralizing the security benefits of the technology.

The implications of this vulnerability are far-reaching, as passkeys have been widely promoted as a more secure alternative to passwords. Many users and organizations have adopted passwordless authentication under the assumption that it eliminates risks associated with phishing and credential stuffing. However, these findings suggest that if the device itself is compromised, the security model can be circumvented entirely. This undermines confidence in the robustness of current passkey implementations.

BleepingComputer reported on 'Pass-ta-key' attacks, which specifically target the synchronization layer of Google’s password management system. The malware exploits the trust relationship between devices to steal credentials without alerting the user. Since the process occurs silently in the background, users may remain unaware that their passkeys have been compromised until unauthorized access is detected.

Security experts emphasize that this issue is not limited to a specific type of malware but represents a systemic flaw in how synced passkeys are handled. The vulnerability affects any user who enables synchronization for their passkeys within Google services. This broad exposure increases the potential impact, as millions of users rely on these features for convenience and security across multiple platforms.

The discovery has prompted urgent calls for patches and improved security measures from Google. While no immediate fix has been detailed in the initial reports, the severity of the vulnerability suggests that significant changes may be required to secure the synchronization process. Developers and users alike are advised to exercise caution and monitor their accounts for suspicious activity.

This incident serves as a reminder that passwordless authentication is not immune to new forms of cyber threats. As attackers adapt to evolving security measures, vulnerabilities in implementation can create unexpected risks. The reliance on cloud-based synchronization introduces dependencies that can be exploited if not properly secured.

Users concerned about this vulnerability may consider disabling passkey synchronization until a patch is available, although this could reduce convenience and cross-device functionality. Alternatively, ensuring that devices are free from malware through regular security scans and updates remains a critical defense strategy.

The broader cybersecurity community is now scrutinizing other passwordless authentication systems for similar flaws. The incident underscores the need for rigorous testing and continuous monitoring of security protocols to stay ahead of emerging threats. As passkeys become more prevalent, addressing these vulnerabilities will be essential to maintaining trust in digital identity management.

Sources behind this briefing

Go to the original reporting

  • Unit 42↗Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
  • The Hacker News↗Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
  • CyberSecurityNews↗Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint
  • BleepingComputer↗New Pass-ta-key attacks let malware hijack Google-synced passkeys