Google Passkey System Vulnerable to Malware Attacks
Security experts have discovered vulnerabilities in Google's passkey system that could allow malware to steal and use user authentication credentials. The findings, made by Unit 42 researchers, indicate that attackers can bypass Chrome-based passkeys using techniques called 'Pass-ta-key.' These attacks target weaknesses in how Google Password Manager handles passkeys on compromised Windows machines.
The 'Pass-ta-key' method involves stealing a protected account from an infected device. Instead of the security key being properly protected by hardware features, malware can export the identity key and use it to authenticate itself. This allows attackers to convince the lock that they are the legitimate user.
A second attack, known as 'silver,' tricks Google Password Manager into believing a user has already approved access with biometrics. The computer remains in an unfinished verification state, allowing malware to register its own keys. This means future authentication attempts could approve the attacker's keys as if they belonged to the real user.
The most concerning method is the 'golden' attack, which involves stealing information from Chrome's internal processes. If malware can extract sensitive encryption data connected to Google Chrome's passkey system, it may be able to access a user's synced passkeys. This stolen information could potentially become a blueprint for decrypting future passkeys created through Google Password Manager.