Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google

Researchers found three ways malware on an already compromised Windows PC can hijack Google-synced passkeys, bypass user checks, and extract every private key in the vault.

Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google

Google’s “uncopyable” passkeys may be easier to steal than promised

google-lawsuite-AI-Scams Google

Passkeys have been pushed as the safer successor to passwords. It promised protection from phishing, credential reuse, and password leaks. Google even claims that it cannot be copied or accidentally handed to someone else. But it might not be as secure as the company wants it to be.

Security researchers (Via BleepingComputer) have now found three ways malware can undermine those promises for passkeys synced through Google Password Manager. The techniques, collectively named Pass-ta-key, target Google Password Manager inside Chrome on Windows computers equipped with a Trusted Platform Module. Every attack requires malware to already be running on the victim’s computer.

The researchers did not break the cryptography behind passkeys. They exploited weaknesses in device trust, account recovery, onboarding, and how services verify that the user actually unlocked their device.

I can log into my Google account on Windows by using a passkey.I can log into my Google account on Windows by using a passkey. Digital Trends

Malware can impersonate your trusted computer

The first Pass-ta-key technique lets malware use Chrome’s TPM-backed device identity to request a valid passkey response from Google’s cloud authenticator. It requires no administrator privileges, biometric scan, PIN, device unlock, or interaction from the victim. Google’s service sees the request as coming from a trusted computer and returns the authentication response needed to sign in.

Websites are supposed to check a flag confirming that the user verified their identity. Unit 42 found that GitHub correctly rejected the attack, while eBay accepted it despite supposedly requiring verification. eBay fixed that gap after the researchers reported it.

The more advanced Silver Pass-ta-key attack can force Chrome to register a verification key controlled by the attacker. That key is then treated as proof that the victim entered a PIN or used biometrics, allowing account access from another computer after the original device goes offline.

Google account prompt explaining passkeys.Digital Trends

The worst attack steals the keys themselves

The Golden Pass-ta-key technique targets the master secret used to encrypt every passkey synced through a Google account. Researchers initially found that Chrome exposed this secret in plain text through its internal FIDO logs. Google removed it from the logs following disclosure. However, Unit 42 says the key still temporarily appears inside Chrome’s process memory during device registration or recovery. Malware can extract it and decrypt the victim’s synced passkeys.

The stolen master key could reportedly expose existing and future passkeys. Unit 42 adds that Google’s current implementation provides no method to rotate or revoke that secret after it has been compromised. Passkeys remain substantially safer against phishing and password leaks. Google’s documentation still accurately describes those advantages. This research shows that malware already inside your computer can attack the infrastructure surrounding the passkey instead.

Vikhyaat Vivek

Vikhyaat Vivek is a tech journalist and reviewer with seven years of experience covering consumer hardware, with a focus on…

Apple will finally stop making iPhone-to-Windows copy-paste such a chore

Your iPhone may finally copy and paste with a Windows PC like it should

Apple Universal Clipboard feature

Copying something on an iPhone and pasting it onto a Windows PC should be one of the least remarkable features imaginable. While this simple process seems effortless between an iPhone and Mac, Windows users are still left waiting.

Now, Microsoft is formally asking Apple to provide interoperable clipboard access through the company’s European Union interoperability process. The request, submitted on March 25, argues that iOS restrictions prevent third-party platforms from creating an experience comparable to Apple’s Universal Clipboard. Apple has now reached Phase III and committed to developing a solution.

Read more

Chrome wants more extension reviews, but good ratings won’t keep malware out

Google is testing built-in extension review prompts, but good ratings can still hide malware

malicious-google-chrome-extensions-on-web-store

Google is preparing to add extension review links directly inside Chrome, putting feedback closer to the menus people already use to manage their add-ons.

A Chromium change, first spotted by Windows Report, points to review options in the Extensions menu, the chrome://extensions management page, and extension context menus. Only eligible Chrome Web Store extensions in good standing would qualify, and the feature is still under development.

Read more

Apple’s OpenAI lawsuit just tripped over an embarrassing wrong-recipient email

Apple came for OpenAI’s trade secrets, but OpenAI had email receipts

OpenAI

Apple and OpenAI’s legal battle has quickly moved beyond carefully worded court statements. OpenAI has just shared the email and message trails behind the dispute, and one exchange leaves Apple’s version of events looking questionable.

In a bluntly titled post, “Apple is getting this wrong,” OpenAI challenged Apple’s request for a preliminary injunction and accused the iPhone maker of building parts of its case around false or incomplete information. Apple wants a court to prevent OpenAI and two former Apple employees from accessing, acquiring, using, or disclosing its alleged confidential information.

Read more