Google synced passkeys on Windows can be stolen by malware already on the device
Researchers found that if a Windows computer is already infected, harmful software may be able to take control of Google account sign-ins saved and synced through Chrome without needing a password, fingerprint, or approval prompt. This could let an attacker access accounts more quietly than many people expect.
Who is at risk
People who use a Windows computer and rely on Google or Chrome to save and sync sign-ins across devices are most at risk, especially if their computer may already be infected.
What to watch for
Watch for unusual account activity such as sign-in alerts, security setting changes, new devices appearing on your account, or messages sent from your account that you did not authorize.
What to do
Immediately run a full security scan on your Windows computer, install all system and browser updates, and review your Google account for unfamiliar devices or recent sign-ins.
