// Alert

Gmail threat report

Security researchers revealed attacks called "Pass-ta-key" that enable malware on compromised Windows devices to hijack Google accounts protected by synced passkeys, bypassing password and biometric authentication. Three techniques exploit Chrome's passkey storage, device trust mechanisms, and recovery workflows to gain valid authentication assertions. The threat requires malware already running on a victim's account but not administrator privileges.

// Get alerts for Gmail