Passkeys are becoming more popular as a safer alternative to traditional passwords, but some cracks are starting to show after one group successfully bypassed Google’s Chrome-based passkeys using what they call the “Pass-ta-key” attack method.
It’s taken some time, but passkeys have become common across apps and websites. The premise is simple and effective – ditch the password string and set up a biometrically locked signature that only your authenticated devices can use to sign in.
As safe as it’s proven to be, one group of researchers known as Unit 42 found that Google’s Password Manager has a couple of buried flaws one could use to bypass everything that makes a passkey safe from attack.
The report states that several different methods were used to bypass the safety mechanisms we get out of a passkey. By coming into effect at the endpoint, certain websites can be tricked into thinking the user’s Chrome-based passkey is authentic, when it’s been hijacked.
The entire premise has a caveat – the Windows machine in question needs to have already been infected with malware. A clean PC won’t be vulnerable when passkeys are used, but the researchers found malicious software can attack passkeys at the authentication stage, even if they were created on a healthy device.







