What does hijacking Google Passkeys mean for users?
Google Password Manager uses passkeys—cryptographic credentials that replace passwords—and secures them behind biometric or PIN verification to protect user accounts. However, security researchers uncovered sophisticated methods where malware present on a device can hijack these passkeys. This allows attackers to bypass biometric or PIN protections, impersonate users, and gain access to all accounts secured with Google’s passkeys.
Understanding this risk is critical because once malware infects a device, it can manipulate Google's system to authenticate as the user without requiring usual confirmation steps. Consequently, all passkey-protected accounts synced via Google Password Manager are vulnerable unless proper precautions are taken.
How do these passkey hijacking attacks work?
The attacks rely on the presence of malware on the victim's device and are technically complex. Researchers described three levels of exploits:
- Pass-ta-key: Malware impersonates the user to log into protected accounts without requiring PIN or biometric input but only on some services.
- Silver Pass-ta-key: The attacker tricks Google into trusting their device directly, removing the need for the victim’s device to be involved during the login.
- Golden Pass-ta-key: The most severe method where malware steals the master secret that encrypts and syncs all passkeys across devices. This secret can be exfiltrated and used later to access all accounts without additional authentication.
These methods exploit trust and synchronization mechanisms in Google’s password management ecosystem and were demonstrated on real platforms like eBay, which subsequently patched the vulnerability.
What limitations and protections currently exist?
Importantly, these attacks require prior malware infection, which means the device is already compromised. If malware is controlling the device, many security safeguards might already be ineffective.
Moreover, not all services are vulnerable to these exploits, and fixes have been or are being implemented by Google and affected services to close these loopholes. For example, certain platforms patched their applications to require proper biometric or PIN verification before accepting passkey-based authentication.
Google’s fixes, while not fully detailed publicly, indicate an ongoing effort to reinforce the security of passkeys and protect the master secret against extraction.
What steps should users take to protect themselves?
- Prevent malware infection: Use reputable antivirus software, keep your operating system and applications updated, and avoid downloading untrusted apps or links.
- Enable multi-factor authentication (MFA): Where possible, add additional verification steps independent of passkeys to protect critical accounts.
- Monitor trusted devices: Regularly review and remove old or unknown devices linked to your Google Account.
- Apply updates promptly: Keep your browsers and password managers updated to the latest versions to benefit from security patches.
- Use hardware security keys: Physical keys can provide an additional layer of security that malware cannot easily bypass.
What this means for Google Password Manager users going forward
The discovery of these advanced passkey hijacking techniques highlights that while passkeys improve security over traditional passwords, their protection depends heavily on device integrity and trusted environments. Users should not assume biometrics or PINs offer absolute protection if a device is already infected with malware.
The key takeaway is to maintain robust device security hygiene and stay vigilant about which devices have access to your accounts. Keeping software up-to-date and minimizing malware risk remain the most effective strategies to safeguard passkeys and, by extension, your digital identity.
As Google continues to address these vulnerabilities, users should anticipate further security improvements but also recognize that no system is impervious when the underlying device is compromised.
