Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
The Hacker News
Read full postUnit 42 researchers revealed three attack methods targeting Google Password Manager's passkey system on Windows, allowing malware to access accounts without user verification. These exploits do not break cryptography but abuse Chrome's key storage and device re-enrollment processes. The vulnerabilities require prior malware presence on the device and affect Chrome on TPM-equipped Windows systems.




