Researchers show ways malware can misuse Google passkeys synced in Chrome on Windows
Researchers found that if harmful software is already running on a Windows computer, it may be able to misuse Google-synced passkeys in Chrome to sign in to accounts or even steal the secret used to protect those sign-ins. Passkeys are still safer than passwords in many cases, but this shows they can be undermined when a device itself is infected.
Who is at risk
People who use Chrome on Windows and store passkeys in Google Password Manager are most at risk, especially if their computer may already have harmful software on it.
What to watch for
Watch for unexpected account sign-in alerts, new device approvals, browser changes you did not make, or a computer that suddenly behaves oddly or runs unknown programs.
What to do
Run a full security scan on your Windows computer, install all Windows and Chrome updates, and review your Google account for unfamiliar devices or recent sign-ins right away.
