{
  "id": 220269,
  "title": "Researchers found a way to steal passkeys straight out of Chrome's memory",
  "url": "https://urgent.news/2026/08/06/researchers-found-a-way-to-steal-passkeys-straight-out-of-chromes",
  "topic": "science",
  "section": "Science",
  "published": "2026-08-06T13:09:00.000Z",
  "source": {
    "name": "TechSpot",
    "slug": "techspot",
    "url": "https://www.techspot.com/news/113375-researchers-found-way-steal-passkeys-straight-out-chrome.html"
  },
  "original_language": "en",
  "account": "Tech companies are moving away from passwords to passkeys due to their enhanced security and ease of use. However, researchers from Unit 42 have revealed that passkeys stored in Google Chrome can be compromised. There are three methods by which malware on a PC can steal passkey data.\n\nThe most severe method allows the attacker to completely take over the victim's Google passkey vault, granting them remote access to all accounts protected by passkeys. The second method involves deleting a specific file in Chrome, which forces the cloud service to re-authenticate the target device. The attacker can then issue a new key to gain access to all protected accounts.\n\nThe third method requires the hacker to intercept a master key during the passkey onboarding process. By doing so, they can gain complete control over the passkey vault. Notably, none of these attacks require privilege escalation or multi-factor authentication. Unit 42 has informed Google about the vulnerability, and they advise passkey authenticator developers to be vigilant for unusual passkey usage, enhance initial registration security, and restrict access to locally stored passkey files.",
  "summary": "Researchers at Unit 42 recently detailed three methods by which malware on a PC can read passkey data stored in Google Chrome. The most severe method completely compromises the victim's Google passkey vault, granting attackers remote access to every account that relies on passkeys. Read Entire Article",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}