Unit 42 details ways malware can bypass passkey prompts in Google Password Manager
Source headline: Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Intelligence Summary
Malware running under an ordinary Windows user can sign into passkey-protected accounts without triggering visible prompts. Unit 42 describes multiple abuse paths targeting Chrome’s Google Password Manager cloud authenticator. The approach, dubbed Pass-ta-key family, can let attackers complete authentication by targeting the master key. Victims may not see fingerprint or PIN prompts on their screens during login. This matters because passkey-protected accounts can be compromised through workflow abuse rather than stolen user input, so users should review endpoint security and harden browser/account controls.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.