Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

A serious vulnerability has been discovered in Google’s Password Manager, which could allow malicious software to hijack accounts protected by passkeys. The flaw, found in both Chrome and Android devices, allows hackers to bypass the usual security checks and steal sensitive information.

The problem lies in a feature called “cross-domain privilege escalation,” which is designed to help developers manage user permissions across different websites and apps. However, this feature can be exploited by attackers to gain elevated privileges on a device, essentially giving them free rein to access sensitive data. According to research, the vulnerability could allow malware to steal passkeys used for 2FA (two-factor authentication) and other secure accounts.

The attack vector involves an attacker creating a malicious website or app that tricks the user into granting it excessive permissions. Once the user has granted these permissions, the malware can use them to bypass security checks on the device, effectively rendering any subsequent security measures useless. This could allow hackers to access sensitive information such as email accounts, financial data, and even encrypted storage.

What’s alarming is that this vulnerability affects not just Google users but also anyone who uses passkeys for 2FA. The reason is that the problem lies in the way Chrome and Android handle cross-domain requests, which can be exploited regardless of the password manager being used. This means that users on other platforms may also be at risk.

The discovery of this vulnerability highlights a significant flaw in the current state of online security. While passkeys are meant to provide an additional layer of protection, they can only do so if the underlying infrastructure is secure. In this case, it seems that Google’s implementation of cross-domain privilege escalation has left users vulnerable to attack.

So what does this mean for users? First and foremost, it’s essential to recognize that no security measure is foolproof. Users should always be on the lookout for suspicious activity on their devices and report any unusual behavior. Additionally, using a reputable antivirus software can help detect and prevent malware from gaining access in the first place.


Source: The Hacker News — 2026-08-03