Google Password Manager Flaw Exposes Passkey Accounts to Malware
New research reveals critical vulnerabilities in Chrome's Google Password Manager that could allow malware to bypass passkey authentication entirely. Attackers can gain access without requiring any user interaction or biometric verification.
TL;DR
- Malware can hijack passkey-protected accounts without user interaction
- Three attack vectors identified: Pass-ta-key, Silver Pass-ta-key, Golden Pass-ta-key
- Golden Pass-ta-key targets the master encryption key for maximum impact
- No fingerprint, PIN, or screen prompts required for unauthorized access
- Affects Chrome's Google Password Manager cloud authenticator on Windows
Security researchers have uncovered serious flaws in Chrome's Google Password Manager that could allow malicious software to completely bypass passkey authentication. These vulnerabilities enable attackers to access protected accounts without requiring any form of user verification, including fingerprints or PIN codes.
The attack methods, dubbed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, represent a significant threat to users who rely on Google's password management system for securing their online accounts. The most severe variant targets the system's master encryption key, potentially compromising entire password vaults.
Attack Vectors Explained
- Pass-ta-key allows unauthorized access to individual passkey-protected accounts without user interaction
- Silver Pass-ta-key escalates privileges to access multiple stored credentials
- Golden Pass-ta-key targets the master encryption key, potentially compromising the entire password database
- All attacks work silently without triggering user-facing authentication prompts
- Vulnerabilities specifically affect the cloud authenticator component in Chrome's password manager
Security Implications
- Windows users running standard user-level malware are at risk
- No visible signs of compromise appear on the victim's screen during attacks
- Traditional passkey security assumptions are completely undermined
- Organizations relying on Google Password Manager for employee credential storage face elevated risk
- Immediate patching and enhanced endpoint protection measures are recommended
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.