Chrome Passkeys Become Reusable After Windows Malware
Chrome passkeys on Windows are only as strong as the endpoint that holds their synced state. Once malware already has a foothold, it can turn a passkey login into reusable credential material instead of needing to steal a fingerprint or PIN.
Unit 42 described three Chrome/Google Password Manager paths that let local Windows malware bypass user verification, install an attacker-controlled verification key, or extract the 32-byte Security Domain Secret that decrypts synced passkeys. The result is a valid-looking passkey login from the attacker’s own machine, and the report says the last two paths can survive the original endpoint compromise as reusable access.
The exposure is limited to Chrome with Google Password Manager on Windows systems using a TPM, and it is post-compromise by design. The practical break is that reimaging the device or re-enrolling the browser profile may not remove access if the passkey master state was stolen or replaced.