Google Password Manager Flaw Allows Malware to Bypass Passkey Security and Compromise Accounts

A critical security vulnerability in Google Password Manager enables specialized malware to bypass passkey authentication and hijack protected user accounts. Security researchers discovered that malicious software running with local administrative privileges can intercept and manipulate the local cryptographic key storage used by Chrome and the broader Android ecosystem. By extracting the unencrypted token fragments during local passkey assertion requests, attackers can construct valid authentication signatures without triggering additional biometric checks or security key prompts. The exploit effectively undermines one of the primary selling points of passkeys—their theoretical immunity to credential theft and remote phishing attacks. Cyber-security experts note that while passkeys successfully prevent traditional web phishing, local device compromise remains an entry point if operating system isolation fails to restrict unauthorized memory access. In response to the disclosures, Google confirmed it is rolling out emergency security patches to harden local key protection and improve process isolation across Chrome and Google Play Services, while advising users to ensure their devices remain updated and protected by active endpoint security software.

Leave a Reply

Your email address will not be published. Required fields are marked *