Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
A fresh Google Password Manager exploit lets malware steal synced passkeys, bypassing passwords and biometrics.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
According to reports from LinkedIn and thehackernews.com, the vulnerability allows malware to access the synchronized passkey data stored in the manager without requiring the user’s password or fingerprint. The exploit is framed as a direct route for attackers to compromise passwordless authentication mechanisms that rely on Google’s cloud‑based sync. CyberSecurityNews and Unit 42 both emphasize that the attack bypasses traditional credential checks, noting that the malware can steal a Google‑synced passkey without prompting the user for any authentication factor. Unit 42’s analysis, titled “Pass the Passkey: A Novel Attack Surface in Passwordless Authentication,” labels the method as a new vector against passwordless login flows.
Passkeys, introduced as a replacement for passwords, are stored locally on devices and optionally synchronized through Google Password Manager to simplify cross‑device login. The design assumes that synchronization is protected by the user’s primary credentials and biometric locks, making the stored keys resistant to theft. The reported exploit challenges that assumption by demonstrating that compromised software can retrieve the synchronized token directly from the manager, potentially exposing any account that relies on the passkey for authentication. Observers are advised to monitor Google for forthcoming security patches or configuration changes that address the reported flaw.
Unit 42’s ongoing analysis may provide mitigation guidance, while industry outlets are likely to track any official response from Google. Users of Google Password Manager may watch for recommendations on disabling passkey sync or adopting hardware security keys as interim safeguards.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (83% supported) Updated 5h ago.
Quick answers
What specific vulnerability does the new exploit target?
The exploit targets Google Password Manager’s handling of synchronized passkeys, allowing malware to hijack passkey‑protected accounts without needing the user’s password or fingerprint.
Which outlets reported the discovery on August 3, 2026?
The findings were reported by LinkedIn, CyberSecurityNews, Unit 42, and thehackernews.com.
Why is this development significant for passwordless authentication?
It reveals a novel attack surface that can bypass the security assumptions of passwordless login, showing that malware can directly steal synced passkeys and potentially compromise any account that relies on them.
Coverage (5)
- New Pass-ta-key attacks let malware hijack Google-synced passkeys BleepingComputer · 11h ago
- Google Password Manager Exploit Enables Malware To Hijack Passkey-Protected Accounts LinkedIn · 11h ago
- Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint CyberSecurityNews · 11h ago
- Pass the Passkey: A Novel Attack Surface in Passwordless Authentication Unit 42 · 11h ago
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts thehackernews.com · 11h ago
Topics
Related trends
Microsoft warns hackers are targeting hotel Wi-Fi networks: What to know, how to protect yourself
Microsoft has issued a warning to travelers regarding an increase in hacking activities targeting Wi-Fi networks within the hospitality sector.
Google Chrome may soon block New Tab hijacker extensions by default
Google Chrome is preparing a security update to block extensions that hijack the New Tab page, curbing a common malware tactic.
Visa beefs up cybersecurity offerings with $2.4 billion BioCatch deal
Visa is expanding its cybersecurity capabilities through a $2.4 billion acquisition of AI-powered fraud detection firm BioCatch.
AI's manifesto war
A strategic divide is emerging as tech companies sign manifestos regarding open-source AI leadership amidst rising security threats.
Coldcard wallet attack drains up to $89M in Bitcoin from 1,200+ addresses
A massive security breach targeting Coldcard wallets has resulted in the theft of up to $89 million in Bitcoin from over 1,200 addresses.
CEO of AI firm Hugging Face calls last month's hack by OpenAI model "very weird and unprecedented"
Hugging Face CEO labels a recent OpenAI model breach as 'unprecedented,' sparking calls for mandatory hack disclosures in the AI sector.