Malware Can Hijack Google-Synced Passkeys via Pass-ta-key Attacks
Researchers discovered three attack techniques that exploit weaknesses in how Google Chrome and Google's cloud authenticator handle device trust and credential syncing, allowing malware on a compromised Windows device to steal or hijack passkeys synced across a user's Google account. The core problem is that syncing passkeys to the cloud reintroduces centralized credential risk that passkeys were designed to eliminate — if a relying party or authenticator fails to enforce strong user verification and device-bound trust, the phishing-resistance guarantee breaks down. Services like eBay were found to improperly validate user verification signals, making them susceptible to account takeover without the user's knowledge. This matters because passkeys are being widely adopted as a phishing-resistant MFA replacement, and undermining their trust model at scale could erode confidence in next-generation authentication just as adoption is accelerating.
Tactical Insight
Immediate actions
- Audit all applications accepting passkey authentication to verify they enforce strict user verification (UV) flag validation server-side.
- Ensure endpoint protection is up to date to detect and block malware that could access Chrome's local credential store.
- Review and restrict which Google account sync features are enabled on corporate-managed devices via MDM/policy.
Long-term improvements
- Prefer device-bound, hardware-backed passkeys (e.g., FIDO2 security keys) over cloud-synced passkey implementations for high-value accounts.
- Implement application-layer controls that re-verify user presence and intent for sensitive operations even after passkey authentication.
- Establish a formal authentication security review process that evaluates relying-party UV flag enforcement before deploying new authentication flows.
Detection measures
- Monitor for anomalous access patterns following passkey authentication events, such as logins from unexpected geolocations or devices.
- Enable logging of all authenticator interactions and set alerts for unusual credential export or sync activity from endpoint systems.
- Subscribe to threat intelligence feeds covering authentication bypass and credential-hijacking techniques to stay ahead of evolving attack vectors.