Breaking
Live threat feed August 18, 2026 | 08:28 UTC
6430 CVEs This Month
10 Actively Exploited
0 Ransomware Activity
34 Breaches YTD
Threat Investigation Portal
Investigate an IOC in the live graph workspace.
Investigate IOC
Vulnerabilities

Researchers Uncover Malware Attacks Exploiting Google Password Manager Synced Passkeys

Researchers Uncover Malware Attacks Exploiting Google Password Manager Synced Passkeys

Security researchers have identified three new attacks where malware present on already compromised Windows devices abuses Google Password Manager's synced passkeys. These attacks enable threat actors to bypass user verification, hijack accounts, and extract private passkey credentials from the device.

What happened

Researchers discovered three distinct attack techniques targeting the Google Password Manager feature that syncs passkeys across devices. These attacks can be executed by malware that has already gained a foothold on a Windows machine. Once the device is compromised, the malware can leverage these methods to extract sensitive private keys associated with passkeys, effectively bypassing standard user verification processes.

The abuse of Google Password Manager's syncing functionality allows attackers to escalate their access, potentially taking over user accounts without requiring additional authentication factors. Such a capability significantly strengthens the attackers' control once initial compromise is achieved on a Windows device.

Why it matters

Passkeys, promoted as a secure alternative to passwords, rely on private keys stored on user devices to authenticate identity without exposing secrets to attackers. The discovery that malware can hijack these passkeys undermines this security paradigm, especially when the device is already compromised.

Since many users and organizations adopt password managers with synced passkeys for convenience and enhanced security, these attacks could have widespread implications. They highlight the continuing importance of endpoint security, as even strong authentication methods remain vulnerable if the underlying devices are compromised.

What security teams should do

Defenders should prioritize preventing initial device compromise through endpoint protection measures and maintaining up-to-date security patches on Windows devices. Monitoring for suspicious activity related to Google Password Manager or unusual access patterns may help detect exploitation attempts.

Until further mitigations or patches are offered, organizations should consider limiting the syncing of passkeys on devices with elevated risk or enforce stronger security controls around credential storage and retrieval processes. Reviewing vendor guidance from Google on best practices for passkey management is also advisable.

Key technical details

The three attacks exploit malware capabilities on Windows to interact with Google Password Manager's synced passkey data. One attack enables extraction of private keys from the compromised device, facilitating credential theft.

Another method bypasses user verification prompts that would normally protect passkey usage. The combined effect allows attackers to perform account takeovers by leveraging stolen passkey credentials synced through Google Password Manager, without needing additional authentication steps.

Affected organizations/products

These attacks target Windows devices where Google Password Manager is used to sync passkeys. Users who rely on this feature for passwordless authentication and have their devices compromised by malware are at risk. No specific organizations were identified in the report.

Source attribution

https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/

Thirumala Rao Padilam
Written by
Thirumala Rao Padilam
error: Content is protected !!