Passkeys in Google Chrome Are Open to Attack, With One Big Caveat

Security researchers at Palo Alto Networks have discovered a vulnerability in Google Chrome that allows malware to bypass passkey security. By reading plaintext data from the Google Password Manager, attackers can manipulate the cloud authenticator to falsify authentication.
<p>Researchers found a way to bypass Chrome's passkey security and steal the codes directly from the browser of a PC infected by malware.</p><p>The big reason <a href="https://www.pcmag.com/explainers/still-using-passwords-its-time-to-upgrade-to-passkeys" target="_self">passkeys</a> are safer is that they can't be stolen, copied, or guessed. There's no way to social engineer a passkey that can then be used remotely. But if the device the passkey is stored on is compromised, that can be a real problem. In this case, researchers from Palo Alto Networks' <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" title="(Opens in a new tab)">Unit 42</a> were able to read enough plaintext data from <a href="https://www.pcmag.com/how-to/how-to-master-google-password-manager" target="_self">Google's Password Manager</a> to manipulate the cloud authenticator and access whatever the passkey protected. </p><p>This attack, dubbed Pass-Ta-Key by Unit 42, can mimic how Chrome and Google <a href="/picks/the-best-password-managers" data-element="link-injector" x-track-ga-click>Password Manager</a> interact to falsify a passkey authentication, making it appear as if a passkey has been seen and approved when it has not.</p><div class="mb-0 rounded-md bg-gray-100 p-3 md:p-5" id="related-video">
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in