None
TL
Passkeys in Google Chrome Are Open to Attack, With One Big Caveat
['About Our Expert']
PCMag Australia
Researchers found a way to bypass Chrome's passkey security and steal the codes directly from the browser of a PC infected by malware.
The big reason passkeys are safer is that they can't be stolen, copied, or guessed.
It works similarly to traditional mobile password reset attacks, forcing the registration of a new authentication key that attackers can access.
Using the same spoofing method as in the Silver attack, the attacker dumps Chrome's process memory and extracts the master key that protects the passkey's private key.
Using previously acquired information from Chrome's sync database, the attacker can then extract the master key and decrypt the passkey's credentials.