Technology

Google Password Manager Passkeys Vulnerable to 'Pass-ta-key' Attack

9to5Google1h
THE BRIEF
1

Security researchers at Unit 42 have identified a new 'Pass-ta-key' attack that could allow malware to hijack passkeys stored in Google Password Manager.

2

The vulnerability allows attackers to bypass password and biometric authentication, potentially compromising user accounts without triggering standard security alerts.

3

Google is currently investigating the flaw, and users are advised to enable additional multi-factor authentication layers until a security patch is released.