Google Patching Critical Passkey Flaw Allowing Malware to Steal Credentials
AI-generated from multiple sources. Verify before acting on this reporting.
SAN FRANCISCO — Google on Tuesday disclosed a critical security vulnerability in its Password Manager that allows malware to steal synchronized passkeys through three distinct attack scenarios, prompting an immediate patch for users worldwide. The flaw exploits weaknesses in how the software synchronizes and trusts digital credentials without sufficient verification on the server side.
Researchers identified the breach mechanism late Monday, revealing that malicious actors could compromise user accounts protected by what was considered a more secure alternative to traditional passwords. Unlike standard text-based passwords, passkeys rely on public-key cryptography and are designed to be immune to phishing attacks. However, the discovered vulnerability bypasses these protections by targeting the synchronization process between devices.
The attack scenarios involve malware installed on a user's device intercepting credentials as they sync across Google services. In two of the three identified methods, attackers can extract passkeys directly from the local storage before encryption is fully applied or during transmission to backup servers. The third scenario involves tricking the system into trusting a malicious request by exploiting gaps in server-side validation protocols.
Google confirmed that the vulnerability affects users who have enabled synchronization for their passkeys across multiple devices using Google Password Manager. Once compromised, these stolen credentials grant attackers full access to any account secured by the affected keys, including email, cloud storage, and financial services linked through the platform.
The tech giant has released an emergency update addressing all three attack vectors. The patch introduces stricter server-side verification requirements for passkey synchronization requests and enhances local encryption protocols on supported operating systems. Users are urged to apply the update immediately via their device settings or browser extensions.
Security experts note that while the vulnerability is severe, it requires malware already present on a user's system to execute successfully. The flaw does not allow remote exploitation without prior access to the victim's hardware. However, the incident highlights potential risks in the rapid adoption of passkey technology as industry standards evolve faster than implementation safeguards.
Google stated that no evidence suggests the vulnerability has been actively exploited by criminal groups at scale before its discovery. Nevertheless, the company is reviewing other areas of its authentication infrastructure to ensure similar weaknesses do not exist elsewhere.
Questions remain regarding whether any user data was compromised during the window between the flaw's creation and Tuesday's disclosure. Google declined to comment on specific incidents but emphasized that users who have already updated their systems are protected against known variants of this attack. The company is working with security researchers to monitor for new exploits as the patch rolls out globally.