importantSYS.SOURCE: The Hacker News• 2026-08-03T21:54:47+05:30
Google Password Manager Vulnerabilities Allow Malware to Bypass Passkey Authentication
Google Password Manager vulnerabilities enable malware to bypass passkey authentication by exploiting key storage and re-enrollment flaws in Chrome on Windows. The attacks extract security domain secrets and manipulate user verification flags to gain unauthorized access to protected accounts.
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen.
Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key
*** END OF TRANSMISSION ***