news.mlab.sh
Back to the feed
threat-intel

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

High
Image: Palo Alto Unit 42
Summary

This report details a new attack vector, dubbed ‘Pass-ta-key,’ that allows malware running on a compromised endpoint to bypass traditional security measures and gain unauthorized access to passkey-protected accounts. Researchers at Palo Alto Unit 42 discovered that malware can exploit vulnerabilities in Google’s synced passkey ecosystem, specifically within the Cloud Authenticator, to extract private keys and impersonate legitimate devices. The attacks bypass user interaction, device unlock, and PIN verification, presenting a significant threat to the growing adoption of passkey authentication. The core issue lies in the ability of malware to extract and use the device’s identity key, a process that can be accomplished without elevated privileges, making it a particularly insidious risk.

Read the full article at Palo Alto Unit 42

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.