ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Unit 42 details ways malware can bypass passkey prompts in Google Password Manager

Source headline: Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

Malware running under an ordinary Windows user can sign into passkey-protected accounts without triggering visible prompts. Unit 42 describes multiple abuse paths targeting Chrome’s Google Password Manager cloud authenticator. The approach, dubbed Pass-ta-key family, can let attackers complete authentication by targeting the master key. Victims may not see fingerprint or PIN prompts on their screens during login. This matters because passkey-protected accounts can be compromised through workflow abuse rather than stolen user input, so users should review endpoint security and harden browser/account controls.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#malware #windows #cloud-authentication #browser-security #credential-access #passkeys
Original reporting The Hacker News Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Open original source