None
CY
Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
['Pieter Arntz']
Malwarebytes
Passkeys were supposed to make stolen passwords a thing of the past.
Malware comes into playThe researchers, however, started with a malware infected Windows computer and came up with three possible attack scenarios to steal Google synchronized passkeys.
Silver Pass‑ta‑key : malware abuses device re‑enrollment to register its own user‑verification key, then logs in as the victim from the attacker’s machine without touching the victim’s device.
Golden Pass‑ta‑key: Malware extracts Google’s security domain secret (the master encryption key), decrypts all synced passkeys, and can reuse them anywhere, even after losing access to the original device.
For end users, passkeys still offer strong protection against classic phishing websites and credential stuffing attacks based on reused passwords.