← Back to Tech & Science

Researchers Identify Critical Flaws Allowing Malware to Bypass Chrome Passkey Security

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SAN FRANCISCO (AP) — Cybersecurity researchers have identified three distinct attack vectors that allow malware running on a Windows machine to hijack passkey-protected accounts in Google's Password Manager within the Chrome browser without requiring user verification. The discovery, detailed by Unit 42 of Palo Alto Networks on Monday, highlights a significant vulnerability where malicious software can bypass the biometric or PIN-based authentication mechanisms designed to secure digital identities.

The flaws enable an attacker who has already compromised a Windows system with malware to initiate login requests that appear legitimate to the browser. In these scenarios, the malware interacts directly with Google's Password Manager APIs to retrieve and use stored passkeys for services such as email, banking, or social media platforms. Unlike traditional password theft, which often requires tricking a user into entering credentials on a fake site, this method exploits the trust relationship between the operating system and the browser extension.

Google has acknowledged the findings regarding its Chrome Password Manager integration. The company stated it is working to address the vulnerabilities through upcoming security updates for both Windows and macOS versions of the browser. Google emphasized that passkeys remain more secure than traditional passwords because they are resistant to phishing attacks, but noted that local malware presents a unique threat vector when an attacker has already gained control of a device.

The three identified attack paths involve different methods of manipulating the authentication flow. In one scenario, the malware intercepts prompts generated by websites requesting passkey verification and automatically approves them using credentials stored in the browser's secure enclave. Another path involves exploiting permissions granted to legitimate extensions that have been compromised or misconfigured, allowing unauthorized access to cryptographic keys. A third method utilizes a race condition where malicious code executes before the user has an opportunity to deny a permission request.

Security experts note that while passkeys were introduced as a more robust alternative to passwords by eliminating reliance on memorized strings of characters, they are not immune to local system compromises. The effectiveness of these attacks depends entirely on the malware's ability to execute commands with sufficient privileges on the infected machine. Once inside, the malicious software can silently authenticate users across multiple services without triggering standard security alerts.

The immediate impact remains unclear as no widespread exploitation has been confirmed in the wild at this time. However, cybersecurity firms warn that threat actors are increasingly targeting high-value accounts where passkeys provide a false sense of invulnerability. The specific motivation behind these vulnerabilities and whether they have already been weaponized by criminal groups or state-sponsored hackers is currently unknown.

Google advises users to keep their browsers updated and to employ endpoint protection software capable of detecting malicious activity on Windows systems. Until patches are fully deployed across all user bases, the risk remains that any malware with local access could potentially unlock passkey-protected accounts without the account holder's knowledge or consent.

Discussion

0 / 2000