← Back to Feed
New Pass-ta-key attacks let malware hijack Google-synced passkeys
August 3, 2026 · BleepingComputer · Severity: HIGH
Security researchers discovered three attacks that enable malware on compromised Windows devices to abuse Google Password Manager's synced passkeys. These attacks can bypass user verification, extract passkey private keys, and take over accounts.
Key Takeaways
- Three new attacks abuse Google Password Manager's synced passkeys on Windows.
- Malware can bypass user verification and extract passkey private keys.
- Attacks target already-compromised Windows devices for account takeover.