New Pass-ta-key attacks let malware hijack Google-synced passkeys
Read original article ↗AI Summary
Security researchers from Palo Alto Networks' Unit 42 identified three novel attacks, collectively named 'Pass-ta-key,' that exploit weaknesses in Google Password Manager's handling of passkeys on Windows devices with TPM. The attacks allow malware on an already-compromised device to hijack synced passkeys, impersonate trusted devices, register attacker-controlled verification keys, and extract the master encryption key (security domain secret) from Chrome's memory. While the cryptography of passkeys remains intact, the attacks bypass user verification and enable account takeover, particularly on services that fail to properly validate user verification flags. eBay was found vulnerable but has since patched the issue.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.