← BACK TO FEED
TAG

webauthn1 article

Malware Can Hijack Passkey-Protected Accounts Through Google Password Manager Without Touching Your Screen

Researchers at Unit 42 have identified three attack techniques against Google Password Manager's passkey implementation in Chrome on Windows, which could allow malware already running on a victim's device to silently sign into passkey-protected accounts without any user interaction. The attacks exploit weaknesses in how Chrome stores device keys, handles device re-enrollment, and manages the 32-byte Security Domain Secret used to decrypt synced passkeys — rather than breaking the underlying cryptography. No CVEs have been assigned, the full remediation status is unclear, and it remains unknown whether actions like changing a Google Password Manager PIN would invalidate a secret an attacker has already obtained.

4 Aug 2026