HackerFeeds

CyberSecurity News

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

The Hacker News
· August 3, 2026

AI summary

Malware with ordinary user privileges on a Windows system can access passkey-protected accounts without requiring any additional authentication. This is possible due to vulnerabilities in Chrome's Google Password Manager cloud authenticator. Researchers at Unit 42 have identified three potential attack paths, dubbed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key. The most severe of these attacks targets the master key, allowing malware to sign into accounts without prompting the user for a fingerprint, PIN, or other authentication method. These attacks can occur without any visible prompts on the victim's screen. The vulnerabilities highlight a potential weakness in the security of passkey-protected accounts.

Read the full article at The Hacker Newsthehackernews.com/2026/08/google-password-manager-attacks-could.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.