[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQtm5ecKgnf6qsU4Atjos1CmBhuAOdnddLTYQcb5tosI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"e4bee1bf-fb30-4311-89f0-8ff97bd77099","malware-can-hijack-passkey-protected-accounts-via-google-password-manager-flaws","e9e541f7-96b4-4ede-bc75-8b3d00d6d268","Malware Can Hijack Passkey-Protected Accounts via Google Password Manager Flaws","Researchers identified three attack chains (Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key) that allow malware already present on a Windows machine to steal or abuse passkeys stored in Chrome's Google Password Manager. The root issue lies in how device-bound keys are stored and re-enrolled, combined with insufficient server-side verification by relying parties of whether genuine user authentication occurred. The most severe vector targets the master key protecting synced passkeys, enabling persistent, reusable access with no further user interaction required. This matters because passkeys are widely promoted as a phishing-resistant MFA replacement, and these attacks undermine that trust model if endpoint security is not also hardened.","**Immediate actions:**\n- Audit and restrict local access to Chrome's password\u002Fpasskey storage directories using OS-level access controls and endpoint hardening.\n- Ensure all Windows endpoints running Chrome are fully patched and have up-to-date endpoint detection and response (EDR) tools deployed.\n- Notify users to treat any unexpected re-enrollment or re-authentication prompts for passkeys as a potential compromise indicator.\n\n**Long-term improvements:**\n- Require relying parties (web applications) to enforce strict server-side user verification checks during passkey authentication ceremonies per FIDO2\u002FWebAuthn specifications.\n- Implement hardware-backed key storage (e.g., TPM or platform authenticators) rather than software-based key managers wherever possible to reduce exfiltration risk.\n- Establish a principle of least privilege policy ensuring only authorized processes can interact with credential storage APIs.\n\n**Detection measures:**\n- Deploy behavioral monitoring rules to alert on unexpected access to Chrome's Local State or Login Data files by non-browser processes.\n- Enable centralized logging of passkey re-enrollment events and authentication anomalies for rapid threat detection and investigation.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 6: Access Control Management","CIS Control 10: Malware Defenses","CIS Control 13: Network Monitoring and Defense","NIST SP 800-63B: Digital Identity Guidelines – Authenticator Assurance","NIST AC-3: Access Enforcement","NIST SI-3: Malicious Code Protection","NIST IA-5: Authenticator Management","FIDO2\u002FWebAuthn Level 2 Specification – User Verification Requirements","NIST CSF DE.CM-1: Monitor for unauthorized access and anomalies","published","2026-08-03T18:20:59.604015+00:00","2026-08-03T18:20:59.503+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fgoogle-password-manager-attacks-could.html","google-password-manager-attacks-could-let-malware-hijack-passkey-protected-accou-526442","Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":43,"name":44,"slug":45,"description":46,"color":47},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]