Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
Researchers found three ways malware on an already compromised Windows PC can hijack Google-synced passkeys, bypass user checks, and extract every private key in the vault.
Passkeys were promoted as a more secure alternative to traditional passwords, with the potential to protect users from phishing, credential reuse, and password leaks. Google maintains that passkeys cannot be duplicated or transferred to unauthorized individuals. However, researchers have identified three methods through which malware could compromise the security of passkeys synced through Google Password Manager on Windows devices with a Trusted Platform Module.
These attacks, known collectively as Pass-ta-key, exploit weaknesses in device trust, account recovery, onboarding, and service verification processes. The first technique enables malware to request a valid passkey response from Google's cloud authenticator using Chrome's TPM-backed device identity without requiring any additional authentication from the user.
While Google's services typically flag these requests as coming from a trusted device, eBay accepted one despite its verification requirements. The second attack allows malware to manipulate Chrome into registering a verification key controlled by the attacker, which can then be used to access user accounts even after the original device is disconnected.
Lastly, the third technique targets the master secret used to encrypt passkeys synced through a Google account. Although Google has since removed the secret from Chrome's internal FIDO logs, it may still appear in process memory during device registration or recovery, allowing malware to extract and decrypt the victim's passkeys.
Despite these vulnerabilities, passkeys remain significantly safer than traditional passwords against phishing attempts and password leaks. However, this research highlights the importance of keeping devices up-to-date and patched, as previously unaddressed security flaws can still be exploited by malware.
Written by urgent.news from Digital Trends's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.