ShellCodeX Intelligence Brief
HIGH
Cybersecurity
Malware can hijack Google synced passkeys on compromised Windows PCs
Source headline: New Pass-ta-key attacks let malware hijack Google-synced passkeys
Threat level
High
Signal strength
75/100
Source confidence
1 source
Published
1 hour ago
Intelligence Summary
Security researchers describe three passkey abuse techniques targeting Windows systems already compromised by malware. The malware can leverage Google Password Manager’s synced passkeys to gain unauthorized account access. These methods can bypass normal user verification steps and help attackers obtain passkey private keys. The exposure primarily affects users whose Windows devices are under attacker control and have Google passkeys synced. Users should reduce device compromise risk and review account security protections where possible.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
BleepingComputer
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Open original source