Google Passkeys Security Breach: Malware Steals Master Encryption Key

Published on:

ih featured

Security researchers have uncovered a critical vulnerability in Google Passkeys. Malware can now steal master encryption keys from Google Password Manager. Malwarebytes researchers discovered three distinct attack methods targeting synchronization. The findings reveal that even phishing-resistant passkeys remain vulnerable when underlying software has weaknesses. Passkeys use public-key cryptography with private keys that never leave user devices.

How the Attack Works

Malware infects Windows computers and targets Google-synced passkeys through three techniques. The first method creates valid passkey logins without biometric or PIN prompts. The second method registers attacker-controlled verification keys through device re-enrollment abuse. The third method extracts the Google security domain secret to decrypt all synced passkeys. Google Password Manager syncs passkeys across devices for user convenience.

Three Attack Variants Identified

Researchers named the attack variants Pass-Ta-Key with increasing severity levels. Regular Pass-Ta-Key silently requests valid logins from Chrome and Google cloud. Silver Pass-Ta-Key exploits re-enrollment to register attacker keys for remote access. Golden Pass-Ta-Key steals the master encryption key and decrypts every synced passkey permanently. Each variant builds on the previous one with greater system access.

Golden Pass-Ta-Key Most Dangerous

The Golden variant poses the highest risk because it extracts the master encryption key. Once obtained, attackers can decrypt all synchronized passkeys and reuse them anywhere. Original device access becomes irrelevant after the master key compromise. This attack bypasses all device-level protections completely. Victims cannot revoke access even after discovering the breach. The master key allows unlimited account takeover across all platforms.

Expert Recommendations for Users

Researchers urge all users to patch systems and software immediately. Real-time anti-malware protection must stay current and active at all times. Suspicious attachments and links from unknown sources should never be opened or clicked. Google has been notified about these critical vulnerabilities in their password manager. Users should monitor accounts for unauthorized access attempts regularly. Enable hardware security keys for additional protection against such attacks.

Share This ➥