Passkeys Remain Safer Than Passwords Despite New Malware Attack Techniques
Palo Alto Networks' Unit 42 published three techniques on 3 August 2026 showing how malware can hijack Google-synced passkeys stored in Chrome on Windows, without requiring admin rights or user interaction. The attacks target Google Password Manager's cloud authenticator and the device trust it extends, not the passkey standard itself. Crucially, all three variants require malware to already be running on the victim's device, making this a post-compromise issue rather than a flaw in WebAuthn or FIDO2. The research was limited to Chrome on Windows with a TPM, and other platforms such as macOS, Android, iOS, and third-party managers like 1Password were not tested. Passkeys still eliminate phishing as an attack vector entirely, an exposure that passwords and these new techniques do not share.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in