Google Passkeys Vulnerable to Four Bypass Attacks, Unit 42 Researchers Find
SAN FRANCISCO, Aug. 4 -- A passkey is supposed to be the security industry's answer to the password: no string of characters to type, no credential to steal, no phishing email that tricks you into giving it away. In March 2026, more than 400 million websites had adopted passkey authentication. Google Password Manager alone holds the passkeys for tens of millions of Chrome users worldwide.
Last month, researchers at Unit 42, Palo Alto Networks' threat research division, found four ways to steal them anyway.
The research, published Sunday by Unit 42 researchers at Palo Alto Networks and reported Monday, describes an attack the team calls Pass-ta-key. All four methods target Windows machines already infected with malware, and all four reac...
Click here to read full article from source
To read the full article or to get the complete feed from this publication, please
Contact Us.