Urgent.News

What's breaking now, across thousands of outlets.

Science

Researchers found a way to steal passkeys straight out of Chrome's memory

Researchers at Unit 42 recently detailed three methods by which malware on a PC can read passkey data stored in Google Chrome. The most severe method completely compromises the victim's Google passkey vault, granting attackers remote access to every account that relies on passkeys. Read Entire Article

Researchers found a way to steal passkeys straight out of Chrome's memory

Tech companies are moving away from passwords to passkeys due to their enhanced security and ease of use. However, researchers from Unit 42 have revealed that passkeys stored in Google Chrome can be compromised. There are three methods by which malware on a PC can steal passkey data.

The most severe method allows the attacker to completely take over the victim's Google passkey vault, granting them remote access to all accounts protected by passkeys. The second method involves deleting a specific file in Chrome, which forces the cloud service to re-authenticate the target device. The attacker can then issue a new key to gain access to all protected accounts.

The third method requires the hacker to intercept a master key during the passkey onboarding process. By doing so, they can gain complete control over the passkey vault. Notably, none of these attacks require privilege escalation or multi-factor authentication. Unit 42 has informed Google about the vulnerability, and they advise passkey authenticator developers to be vigilant for unusual passkey usage, enhance initial registration security, and restrict access to locally stored passkey files.

Written by urgent.news from TechSpot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techspot.com →

More in Science

More from Thursday 6 August →