Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets
Date:
Tue, 04 Aug 2026 15:10:00 +0000
Description:
Three Pass-ta-key techniques allowed security researchers to work around biometrics-protected locks.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Palo Alto Networks Unit 42 detailed three Google passkey exploits Attacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeys Google implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directly Security researchers from Palo Alto Networks Unit 42 have found three ways to exploit Google s passkey system and log into peoples PIN- or biometrics-protected accounts.
They named these ways Pass-ta-key, Silver Pass-ta-key, and Golden
Pass-ta-key, each being progressively more dangerous than the previous one. While it sounds mighty dangerous, there are major caveats to the exploit, and some of the holes have been plugged already. Latest Videos From TechRadar Watch full video here: Trusting the wrong device The biggest caveat is that the victims device needs to be infected with malware beforehand. Malware can do all sorts of things, from stealing session cookies to exfiltrating sensitive data, so if a device is tainted with malware, its already in trouble.
Still, Unit 42s findings were important enough to warrant a fix from Google. You may like 'Password reuse only sharpens this problem': Browser-based password storage isn't as safe as you think these top tips from the experts show how it should be done Experts find Google API keys are still usable,
even after you delete them Hackers hijack Google Ads to spread phishing campaign spoofing top GoDaddy tool
In the first technique, the attackers pretend to be the victim. By using malware, they can ask Google to log into a passkey-protected account as if it was the victim themselves. Usually, the service being logged into would require a PIN or a fingerprint to confirm the authenticity of the request,
but in this scenario, that wasnt the case.
The method doesnt work everywhere, though. Unit 42 could not replicate the attack on GitHub, but they succeeded on eBay. The latter later fixed the problem. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
In the second attack, Unit 42 managed to make Google trust the threat actors device, meaning the victims computer was no longer necessary.
In the third attack, the researchers managed to steal the master key.
Google Password Manager syncs the passkeys between devices, and to do that, it uses a master secret that protects all of the synced passkeys. The researchers found that, under certain circumstances, malware can grab this master secret while Chrome is temporarily using it, unlocking all of the synced passkeys, copying them to another computer, and being able to use them at a later date.
The researchers disclosed their findings with Google before publication, and some fixes were already implemented. Google is yet to comment on the findings and confirm that all of the flaws were addressed.
Via BleepingComputer The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/experts-reveal-google-password-manager- can-be-hijacked-to-let-hackers-steal-passkeys-and-gain-access-to-all-your-secr ets
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)