New Pass-the-Key Attacks Let Malware Steal Google-Synced Passkeys

ยท
Listen to this article~5 min

New research reveals three attacks that let malware on Windows devices hijack Google-synced passkeys, bypass verification, and steal private keys. Here's what to do.

If you're using Google Password Manager to sync passkeys across your devices, you might want to sit down for this one. Security researchers just uncovered a set of three attacks that let malware on an already-compromised Windows machine grab your synced passkeys, bypass user verification, and even extract the private keys. That's the digital equivalent of someone finding your house key under the mat, then making a copy while you're asleep. Passkeys were supposed to be the answer to passwords. They're phishing-resistant, they're tied to your device, and they feel futuristic. But here's the catch: convenience often comes with a hidden trade-off. When you sync passkeys to the cloud, you're putting a lot of trust in that sync layer. And trust, as we're learning, can be broken. ### How These Attacks Actually Work The research, which focuses on Windows devices, reveals three distinct attack paths. Each one exploits the way Google Password Manager handles synced passkeys. Here's the breakdown: - **First attack: Bypassing user verification.** The malware tricks the system into thinking you've already confirmed your identity. No fingerprint, no PIN, no face scan. The passkey just gets handed over. - **Second attack: Account takeover.** By hijacking the sync session, the attacker can add their own device to your account. Once that happens, they've got a permanent backdoor that doesn't even need your passkey anymore. - **Third attack: Extracting private keys.** This is the scary one. The malware can directly pull the passkey's private key from the system, which means it can be used offline, on any device, without any further checks. These aren't theoretical flaws. They're practical exploits that work on fully patched, up-to-date Windows machines. The only prerequisite is that your device is already infected with malware. And let's be honest, that's not as rare as we'd like to think. ### What This Means for You If you're a privacy-conscious user, this should raise some eyebrows. Passkeys are a big step forward, but they're not a silver bullet. The real issue here is the sync model. When your passkeys live in the cloud, they become a high-value target. Malware authors know this, and they're already adapting. For professionals who manage multiple accounts, this is especially troubling. A single compromised device could unlock everything. Not just your email, but your banking, your social media, your work accounts. The cascade effect is real. ### How to Protect Yourself Don't panic, but do take action. Here's what I'd recommend right now: 1. **Keep your device clean.** This is the front line. Use reputable antivirus software, keep everything updated, and avoid downloading sketchy files. 2. **Consider hardware keys.** A physical security key like a YubiKey stores passkeys locally, not in the cloud. That eliminates the sync attack surface entirely. 3. **Review your synced devices.** Go into your Google account settings and check which devices have access. If you see anything unfamiliar, revoke it immediately. 4. **Separate high-risk accounts.** If you're a professional handling sensitive data, don't sync those passkeys to the cloud. Keep them on a dedicated, offline device. ### The Bigger Picture The passkey transition is still in its early days. We're trading one set of problems for another. Passwords were hard to remember and easy to phish. Passkeys are easy to use but introduce new attack vectors. The key is staying informed and adapting your strategy. Here's the thing: no single security solution is perfect. The best approach is always layered. Use passkeys where they make sense, but don't put all your eggs in one basket. Combine them with strong device hygiene, and you'll be in a much better position. So, what's the takeaway? Google-synced passkeys are convenient, but they're not invincible. The attacks are real, and they're clever. But with a few proactive steps, you can keep your accounts safe. Stay sharp, stay updated, and never assume you're not a target.