Passkeys can be hacked and that should have Google users worried: What we know

Google has been advocating for passkeys to replace passwords that are easier to hack and bypass. But the company’s password manager is now facing risk from possible attacks that can expose these confidential details to the bad actor.
Show AI Summary
Summarized by AI.Google Passkeys face security risks.
Unit 42 found flaws in Google Password Manager.
Attack requires malware on Windows PCs.
The research from Unit 42 has discovered some weaknesses in Google’s password manager tool that can be bypassed to steal the private data of millions of users. The security firm did a series of tests to check the strength of the actions and used the vulnerability against Password Manager which will have many of the Google users worried.
Latest and Popular Mobiles
What is the issue with Google Password Manager
The Unit 42 team did multiple tests to verify these worrying claims around Password Manager and was finally able to confirm that anybody bypassing these flaws could replace the passkeys and make a website login look authentic.
Related Articles
The tricks used to attack the affected PCs were dynamic and in some cases it was able to mimic a regular login and even assumed that the user had actually unlocked the device using their biometrics which is a key element in the passkey ecosystem.
What should users know about the security risks with Password Manager
The security firm says the flaws in Password Manager cannot be exploited without meeting certain conditions. The research says you need the Windows system already infected by the malware that can enable this attack. If you have a clean PC the passkey attack is less likely but even malicious software in such machines can leave the user vulnerable.
Unit 42 has understandably contacted Google to reveal the concerning details around the Password Manager flaw. But the firm also points that other passkey tools using the same authenticator model can also become a target of these attacks.
Should you still use passkeys?
Security risks are never ending and passkeys, now becoming available across platforms have their first set of concerns. Does this mean you should stop using passkeys and revert back to passwords for your accounts, not really but people should be careful about what websites and files they open, especially if they are sent through unknown sources.







