Home / Technology / Passkey Flaws: Google Accounts Exposed
Passkey Flaws: Google Accounts Exposed
4 Aug
Summary
- Three passkey exploits found by security researchers targeting Google accounts.
- Attacks require prior malware infection on the user's device.
- Fixes have been implemented by Google, with some services patching vulnerabilities.

Security researchers have detailed three exploits, collectively named "Pass-ta-key," that can bypass Google's passkey security measures. These methods require an initial malware infection on the user's device to function.
The first exploit involves impersonating the victim to log into accounts, a method that bypassed security checks on services like eBay before being patched. The second exploit allows an attacker's device to be trusted by Google, negating the need for the victim's device.
The most critical exploit, "Golden Pass-ta-key," enables the theft of a master secret used to sync passkeys across devices via Google Password Manager. Malware can intercept this secret during temporary usage by Chrome, granting access to all synced passkeys. Google has been informed of these vulnerabilities and has implemented fixes.