Vulnerabilities · 54 days ago
Chrome passkeys on Windows are only as strong as the endpoint that holds their synced state. Once malware already has a foothold, it can turn a passkey login into reusable credential material instead of needing to steal a fingerprint or PIN.
Unit 42 described three Chrome/Google Password Manager paths that let local Windows malware bypass user verification, install an attacker-controlled verification key, or extract the 32-byte Security Domain Secret that decrypts synced passkeys. The result is a valid-looking passkey login from the attacker’s own machine, and the report says the last two paths can survive the original endpoint compromise as reusable access.
The exposure is limited to Chrome with Google Password Manager on Windows systems using a TPM, and it is post-compromise by design. The practical break is that reimaging the device or re-enrolling the browser profile may not remove access if the passkey master state was stolen or replaced.
3 sources covering this story
Report: Passkey security issues could allow account takeover
The attacks can misuse trusted workflows to take over passkey-protected accounts, but the attacker must have first breached defenses and planted malware; analysts say the issue is flaws in supporting processes.
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Unit 42 details three Chrome passkey attack paths that could let Windows malware bypass verification or recover synced private keys after compromise.
Part of the PlainSec briefing for 2026-08-05