Google Password Manager
Coverage of Google Password Manager in the Nexus archive.
- Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
Researchers discovered malware can steal Google synchronized passkeys through Google Password Manager, exploiting vulnerabilities in the software despite passkeys being based on public-key cryptography. The 'Pass-ta-key' attacks include scenarios where malware creates unauthorized logins, re-enrolls devices, or decrypts passkeys using a master encryption key.
- New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers discovered three attacks allowing malware on compromised Windows devices to exploit Google Password Manager's synced passkeys, enabling account takeovers and bypassing user verification to extract private keys.
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware on a Windows machine can bypass security measures to access passkey-protected accounts via vulnerabilities in Chrome's Google Password Manager. Unit 42 identified three attack methods, Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, targeting the password manager's cloud authenticator.