Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

August 3, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: Medium
Victim: Windows users of Google Chrome
Incident: Discovery of flaws in Google Password Manager’s implementation of passkey synchronization and verification.
Impact: Potential unauthorized access to passkey-protected accounts without the need for biometric or PIN verification.
Attacker: Unidentified threat actors
Analysis: Researchers identified three methods to exploit Chrome’s handling of TPM-backed keys and the User Verified (UV) flag on Windows. By abusing the Windows CNG API and stored metadata, malware can generate valid authentication assertions without user interaction. This allows attackers to potentially maintain persistent access to passkey-protected accounts from remote environments.
Recommendations: Enforce server-side verification of the User Verified (UV) flag for all passkey authentication requests.; Implement stricter attestation for newly enrolled passkeys to detect unauthorized device registration.; Deploy robust EDR solutions to prevent the initial endpoint compromise required to execute these techniques.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *