Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets



  • Palo Alto Networks’ Unit 42 detailed three Google passkey exploits
  • Attacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeys
  • Google implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directly

Security researchers from Palo Alto Networks’ Unit 42 have found three ways to exploit Google’s passkey system and log into people’s PIN- or biometrics-protected accounts.

They named these ways ‘Pass-ta-key’, ‘Silver Pass-ta-key’, and ‘Golden Pass-ta-key’, each being progressively more dangerous than the previous one.

https://cdn.mos.cms.futurecdn.net/qGbky6N99QiLtik8fjzcUL-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img