// GmailHIGH
Security researchers revealed attacks called "Pass-ta-key" that enable malware on compromised Windows devices to hijack Google accounts protected by synced passkeys, bypassing password and biometric authentication. Three techniques exploit Chrome's passkey storage, device trust mechanisms, and recovery workflows to gain valid authentication assertions. The threat requires malware already running on a victim's account but not administrator privileges.
- Malware Can Steal Google’s Synced Passkeys Without Password or F(opens in a new tab)
- Experts reveal Google Password Manager can be hijacked to let ha(opens in a new tab)
// Get alerts for Gmail