Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

A critical vulnerability in Google’s password manager has been discovered, potentially allowing malicious software to access sensitive user accounts. The flaw, uncovered by cybersecurity researchers, affects users who have enabled passkeys – a feature designed to provide an additional layer of protection against phishing attacks.

The issue arises from the way Google’s password manager interacts with its browser extension. When a user enables passkeys, their login credentials are stored securely on Google’s servers. However, if a malicious actor gains control over a user’s device or browser, they can potentially exploit this vulnerability to intercept and manipulate the passkey. This could allow attackers to bypass standard security measures and access even the most sensitive online accounts.

The researchers who discovered the flaw demonstrated how it could be exploited using a combination of cross-domain privilege escalation and sophisticated social engineering tactics. In their proof-of-concept attack, they were able to bypass Google’s two-factor authentication (2FA) and access a user’s passkey-protected account. The implications are serious: with this exploit, attackers can potentially gain unfettered access to a wide range of online services, including email providers, financial institutions, and social media platforms.

The researchers emphasize that the vulnerability is not specific to Google’s password manager or passkeys alone. Rather, it highlights broader concerns around browser extension security and the potential for malicious actors to manipulate user interactions with sensitive applications. This is particularly alarming given the growing reliance on cloud-based services and the increasing sophistication of social engineering attacks.

While Google has yet to issue a formal statement on the matter, experts are urging users to exercise caution when enabling passkeys or storing sensitive login credentials online. In light of this vulnerability, it’s essential for users to adopt robust security practices, such as using unique, complex passwords for each account and enabling 2FA whenever possible.

As cybersecurity threats continue to evolve, this discovery serves as a timely reminder that even the most well-intentioned security features can be vulnerable to exploitation. By staying informed about emerging risks and adopting proactive security measures, users can better protect themselves against the ever-present threat of online attacks.


Source: The Hacker News — 2026-08-03