New Attacks on Google Passkeys Discovered
Security researchers have discovered three new attacks that enable malware on already compromised Windows devices to exploit passkeys synchronized with the Google Password Manager. These attacks can lead to account takeovers, bypass user verification, and extract private keys from passkeys. The attacks exploit vulnerabilities in the synchronization feature of the Google Password Manager, which allows users to synchronize their passkeys across different devices. If a device is already infected with malware, attackers can use the synchronization to access the passkeys stored on that device.
One specific type of attack identified allows malware to steal user credentials by intercepting the synchronization data. This occurs while the data is being transmitted between the Google service and the affected device. Researchers warn that this method is particularly dangerous as it does not require direct user interaction. Another attack takes advantage of the fact that passkeys are stored in Google Cloud. Attackers can extract passkeys by accessing the cloud data without the user's knowledge.
This technique could enable attackers to access a variety of accounts linked to the Google service. Researchers have also identified a third attack that focuses on authentication methods. This involves bypassing two-factor authentication by intercepting the authentication codes sent to the device. This poses a significant risk to user security, as many users rely on this method to secure their accounts. Google has responded to the discovery and is working on an update to close the security gaps.
The company has emphasized that the security of user data is a top priority and that they are continuously working to improve their security measures. However, a specific date for the update has not yet been announced. Security researchers recommend that users regularly check their devices for malware and take additional security measures to protect their accounts. This includes using strong, unique passwords and enabling two-factor authentication wherever possible. The discovery of these attacks raises questions about the security of cloud-based password managers.
Experts warn that users should be aware of the risks associated with storing sensitive data in the cloud. The attacks could have far-reaching implications for the security of millions of users who rely on Google Password Manager. The vulnerability has been classified under CVE-2026-XXXX, with the exact number yet to be released. Researchers advise keeping a close eye on developments in this area to stay informed about potential security updates.
💬 Comentarii (0)
Inca nu exista comentarii. Fii primul!