Pass-ta-key Attacks Hijack Google-Synced Passkeys on Windows
Researchers uncover Pass-ta-key attack methods that allow malware to hijack passkey-protected accounts on Windows without user interaction.
- Pass-ta-key malware techniques allow attackers to hijack passkey-protected accounts on Windows without user interaction or privilege escalation.
- Affected systems include Windows machines running the Google Chrome browser with synced passkeys.
- Defenders must prioritize endpoint detection for unauthorized access to Chrome synchronization databases and cryptographic APIs.