Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malware Threats to Google Password Manager Accounts Revealed

Malware Threats to Google Password Manager Accounts Revealed

Posted on August 3, 2026 By CWS

Recent research highlights vulnerabilities in Google Password Manager that allow malware to bypass passkey protections on Windows systems. These findings, reported by Unit 42, identify three attack strategies targeting the Google Password Manager within Chrome, potentially compromising user accounts without visible indicators on the victim’s device.

Understanding the Attack Strategies

Unit 42 has identified three critical attack paths: Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key. These strategies exploit how Chrome handles passkey storage, device re-enrollment, and user verification. The attacks do not compromise the underlying cryptography but instead manipulate the code managing passkeys.

The first method, Pass-ta-key, involves accessing Chrome’s device identity key and manipulating Windows Cryptography API calls to sign unauthorized requests. This process bypasses user verification by exploiting a vulnerability in how Chrome handles TPM keys.

Exploring the Silver Pass-ta-key Path

The Silver Pass-ta-key attack focuses on forcing Chrome to re-enroll a device, allowing attackers to register their own user-verification key. This method leverages a gap in security checks where the system fails to verify if a newly registered key originated from secure hardware. Consequently, attackers can conduct future logins without the victim’s device.

Despite these vulnerabilities, the report does not specify if these issues have been addressed in the latest Chrome updates. The research relies on existing Chromium sources to validate some aspects of these vulnerabilities.

Golden Pass-ta-key and Its Implications

Golden Pass-ta-key targets the Security Domain Secret (SDS) within Chrome. Attackers can extract the SDS, thereby decrypting synced passkey private keys. This attack path is particularly concerning as it allows persistent access to user accounts.

Although some mitigations have been implemented, such as eBay’s enforcement of the user verification flag, the vulnerability remains significant. The report suggests that further security enhancements are needed, including hardware attestation checks and securing client memory against such exposures.

As of the latest updates, there is no confirmation on whether all reported vulnerabilities have been resolved. Users and service providers are advised to enforce stringent security measures, such as requiring user verification and validating newly registered keys.

In conclusion, the research emphasizes the importance of robust security practices in mitigating these vulnerabilities. Continuous updates and user education are crucial in safeguarding against potential threats to Google Password Manager accounts.

The Hacker News Tags:Authentication, Chrome vulnerabilities, Cybersecurity, Google Password Manager, Malware, passkey protection, security research, TPM, Unit 42, user verification

Post navigation

Previous Post: Critical TP-Link Router Flaw Allows Remote Attacks
Next Post: Brinks Home Data Breach Unveiled by Hackers

Related Posts

Bridging the Remediation Gap: Introducing Pentera Resolve Bridging the Remediation Gap: Introducing Pentera Resolve The Hacker News
Critical Linux Vulnerability Exposes Systems to Root Attacks Critical Linux Vulnerability Exposes Systems to Root Attacks The Hacker News
Gitea Vulnerability Allows File Access Without Authentication Gitea Vulnerability Allows File Access Without Authentication The Hacker News
Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution The Hacker News
Why Default Passwords Must Go Why Default Passwords Must Go The Hacker News
Active Exploitation Detected in Gladinet and TrioFox Vulnerability Active Exploitation Detected in Gladinet and TrioFox Vulnerability The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark