tech π Google passkeys vulnerable to basic malware attacks
Researchers from Unit 42 found that malware can steal Google-synced passkeys without any PIN or biometric interaction. Three distinct account takeover attacks were demonstrated, with the most severe one extracting every synced passkey from a victim's account. This vulnerability exists because some services trust a verification flag without truly confirming user identity. While Google removed one secret from Chrome logs, device memory remains risky, demanding stronger verification methods. π