Security researchers at Unit 42 have identified a new 'Pass-ta-key' attack that could allow malware to hijack passkeys stored in Google Password Manager.
The vulnerability allows attackers to bypass password and biometric authentication, potentially compromising user accounts without triggering standard security alerts.
Google is currently investigating the flaw, and users are advised to enable additional multi-factor authentication layers until a security patch is released.