Google Chrome's Passkey Security Breached by Researchers
Researchers from Palo Alto Networks' Unit 42 have discovered vulnerabilities in Google Chrome's passkey security, allowing attackers to bypass authentication and steal passkeys. The attack, dubbed Pass-Ta-Key, can mimic how Chrome and Google Password Manager interact to falsify a passkey authentication.
The researchers found that the device storing the passkey is compromised, making it possible for attackers to read plaintext data from Google's Password Manager and manipulate the cloud authenticator to access protected content. This attack works even when user authentication alongside the passkey is required.
In some cases, this is because services don't necessarily require user authentication alongside the passkey. Unit 42 highlights that this attack can be particularly problematic as it can be carried out without human intervention, making it easy to automate and integrate other remote malware.