ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Malware can hijack Google synced passkeys on compromised Windows PCs

Source headline: New Pass-ta-key attacks let malware hijack Google-synced passkeys

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

Security researchers describe three passkey abuse techniques targeting Windows systems already compromised by malware. The malware can leverage Google Password Manager’s synced passkeys to gain unauthorized account access. These methods can bypass normal user verification steps and help attackers obtain passkey private keys. The exposure primarily affects users whose Windows devices are under attacker control and have Google passkeys synced. Users should reduce device compromise risk and review account security protections where possible.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#malware #account-takeover #windows #google #password-manager #passkeys
Original reporting BleepingComputer New Pass-ta-key attacks let malware hijack Google-synced passkeys
Open original source