[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwdJNp7yO07dx9h3ph55uo0hxDsQobmv06veVn2rGmDk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"4f13d7e3-7c7b-473e-8a89-117ba47f6dae","malware-can-hijack-google-synced-passkeys-via-pass-ta-key-attacks","effb95d1-68c6-40db-a1a3-7a2958c6ae52","Malware Can Hijack Google-Synced Passkeys via Pass-ta-key Attacks","Researchers discovered three attack techniques that exploit weaknesses in how Google Chrome and Google's cloud authenticator handle device trust and credential syncing, allowing malware on a compromised Windows device to steal or hijack passkeys synced across a user's Google account. The core problem is that syncing passkeys to the cloud reintroduces centralized credential risk that passkeys were designed to eliminate — if a relying party or authenticator fails to enforce strong user verification and device-bound trust, the phishing-resistance guarantee breaks down. Services like eBay were found to improperly validate user verification signals, making them susceptible to account takeover without the user's knowledge. This matters because passkeys are being widely adopted as a phishing-resistant MFA replacement, and undermining their trust model at scale could erode confidence in next-generation authentication just as adoption is accelerating.","**Immediate actions:**\n- Audit all applications accepting passkey authentication to verify they enforce strict user verification (UV) flag validation server-side.\n- Ensure endpoint protection is up to date to detect and block malware that could access Chrome's local credential store.\n- Review and restrict which Google account sync features are enabled on corporate-managed devices via MDM\u002Fpolicy.\n\n**Long-term improvements:**\n- Prefer device-bound, hardware-backed passkeys (e.g., FIDO2 security keys) over cloud-synced passkey implementations for high-value accounts.\n- Implement application-layer controls that re-verify user presence and intent for sensitive operations even after passkey authentication.\n- Establish a formal authentication security review process that evaluates relying-party UV flag enforcement before deploying new authentication flows.\n\n**Detection measures:**\n- Monitor for anomalous access patterns following passkey authentication events, such as logins from unexpected geolocations or devices.\n- Enable logging of all authenticator interactions and set alerts for unusual credential export or sync activity from endpoint systems.\n- Subscribe to threat intelligence feeds covering authentication bypass and credential-hijacking techniques to stay ahead of evolving attack vectors.",[12,13,14,15,16,17,18,19,20],"NIST SP 800-63B (Authenticator Assurance Levels)","NIST AC-17 (Remote Access)","NIST IA-5 (Authenticator Management)","CIS Control 6 (Access Control Management)","CIS Control 10 (Malware Defenses)","CIS Control 16 (Application Software Security)","FIDO2\u002FWebAuthn Specification – User Verification Flag Enforcement","NIST CSF ID.AM \u002F PR.AC","GDPR Article 32 (Security of Processing – appropriate technical measures)","published","2026-08-04T00:20:24.996802+00:00","2026-08-04T00:20:24.578+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys\u002F","new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys-3356ba","New Pass-ta-key attacks let malware hijack Google-synced passkeys",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":42,"name":43,"slug":44,"description":45,"color":46},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]