Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Unit 42 researchers discovered three attack paths within Google Password Manager in Chrome that could allow malware to hijack passkey-protected accounts without requiring a fingerprint, PIN, or any user interaction. These attacks exploit vulnerabilities related to device key storage, re-enrollment processes, and the Security Domain Secret (SDS). While Google has made some changes to address these issues, including validating the UV bit and logging changes, the researchers found that the underlying vulnerabilities remain unaddressed and that a user’s stolen SDS could persist even after a PIN change. The research highlights the need for relying parties to implement stricter verification checks and credential providers to enhance key attestation and access controls.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
