Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malware Exploits Google Passkey Vulnerabilities

Malware Exploits Google Passkey Vulnerabilities

Posted on August 3, 2026 By CWS

Recent investigations have unveiled significant weaknesses in Google’s passkey security, revealing how malware on compromised Windows systems can hijack synchronized passkeys without needing traditional authentication methods like passwords or fingerprints.

Understanding the Core Vulnerabilities

The critical findings, part of an extensive study on passkey security, highlight vulnerabilities in Google’s Cloud Authenticator. These flaws undermine its device trust and onboarding processes, which are supposed to safeguard user accounts by replacing passwords with secure public-key cryptography.

Passkeys eliminate the need for shared secrets, a common target for phishing and credential-stuffing attacks. However, research from Unit 42 reveals that Chrome retains passkey metadata in an unencrypted format, easily accessible to malware. This allows attackers to identify all services using passkey logins without needing elevated system privileges.

Exploiting Chrome’s Identity Key

Central to this issue is how Chrome handles the “identity key,” a hardware-backed credential meant to authenticate devices with Google’s Cloud Authenticator. The key’s temporary and exportable nature makes it vulnerable to extraction by malware, which can then mimic Chrome’s authentication processes using standard Windows cryptography APIs.

This allows for a seamless passkey login, termed the “Pass-ta-key” attack, which occurs without alerting the user through biometric or password prompts.

Advanced Attack Variants and Implications

More sophisticated exploits have also been identified. The “Silver Pass-ta-key” attack circumvents user verification by tampering with local passkey records, compelling Chrome to accept a new, attacker-controlled verification key. This could grant attackers ongoing access to accounts, even those protected by multi-factor authentication.

The “Golden Pass-ta-key” attack targets the master encryption key, or security domain secret (SDS), which protects all synchronized passkeys. Researchers found that this critical 32-byte key is exposed in Chrome’s logs and memory during device recovery, enabling attackers to decrypt all associated passkeys.

Despite these issues not compromising the fundamental cryptography of passkeys, they exploit mismatches between design assumptions and real-world implementations. Some services, such as eBay, have already addressed these gaps following responsible disclosure.

Recommendations for Enhanced Security

Security experts recommend strict enforcement of user-verification checks, validation of device key attestations, restricted local access to credential stores, and vigilance against unexpected onboarding or recovery processes.

As cyber threats continue to evolve, integrating robust threat detection tools and practices into security operations centers (SOCs) is crucial for maintaining secure environments.

Cyber Security News Tags:Chrome vulnerabilities, Cloud Authenticator, Cybersecurity, data protection, device trust, Encryption, Google passkeys, identity key, Malware, multi-factor authentication, passkey attacks, passkey security, SDS, Unit 42, user verification

Post navigation

Previous Post: Liechtenstein’s Company Register Data Breach Exposed
Next Post: Malicious npm Packages Target Alibaba Users with RAT

Related Posts

Cursor AI Code Editor RCE Vulnerability Enables “autorun” of Malicious on your Machine Cursor AI Code Editor RCE Vulnerability Enables “autorun” of Malicious on your Machine Cyber Security News
Developing Collaborative Threat Intelligence Sharing Frameworks Developing Collaborative Threat Intelligence Sharing Frameworks Cyber Security News
AI Pentesting Tool that Autonomously Checks for Code Vulnerabilities and Executes Real Exploits AI Pentesting Tool that Autonomously Checks for Code Vulnerabilities and Executes Real Exploits Cyber Security News
Beware of New back-to-school Shopping Scams That Tricks Drives Users to Fake Shopping Sites Beware of New back-to-school Shopping Scams That Tricks Drives Users to Fake Shopping Sites Cyber Security News
HPE Aruba 5G Vulnerability Allows Credential Theft HPE Aruba 5G Vulnerability Allows Credential Theft Cyber Security News
Microsoft Confirms Teams Outage for Users, Investigation Underway Microsoft Confirms Teams Outage for Users, Investigation Underway Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT
  • Malware Exploits Google Passkey Vulnerabilities
  • Liechtenstein’s Company Register Data Breach Exposed
  • INC Ransomware Exploits SonicWall Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT
  • Malware Exploits Google Passkey Vulnerabilities
  • Liechtenstein’s Company Register Data Breach Exposed
  • INC Ransomware Exploits SonicWall Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark