Google Passkey Attack Exposes Weakness in Enrollment Process
A recent discovery has exposed a vulnerability in Google's passkey enrollment process. Abnormal AI researchers found that attackers can exploit this weakness to retain access to a Google account even after its password is changed.
The iAuthFlow v2 toolkit, advertised on a Russian-language cybercrime forum for $10,000, allows an attacker to access a Google account through a phished login and register a separate passkey. The toolkit seller demonstrates how this can be done by accessing the account using a weaker authentication method and then registering a new credential.
The demonstration shows that the attack depends on two separate browser environments: one for the target and another controlled by the attacker. This allows the attacker to communicate with the actual authentication service, even if the target has already registered a passkey.
Google's documentation states that newly registered credentials may require a waiting period of up to 7 days before they can be used for sign-in. The company also notes that it can restrict authentication methods that appear to have been added without the account holder's permission.