Passkeys Aren't Foolproof: New Malware Attacks Target Google's Synced Passkeys
Passkeys have been widely promoted as a safer, phishing-resistant alternative to passwords, but new research shows they aren't entirely immune to attack. Researchers at Palo Alto Networks have demonstrated methods that allow malware to hijack accounts protected by Google's synced passkey implementation, undermining the assumption that passkeys eliminate account takeover risks altogether.
Synced passkeys are designed for convenience, allowing users to access the same passkey across multiple devices by storing it in the cloud, typically tied to a Google, Apple, or Microsoft account. While this makes passkeys easier to use, it also means that if the underlying account or device is compromised by malware, attackers may find new ways to exploit that access chain to take over accounts that were thought to be well protected.
This research is a reminder that no single security technology is a complete solution on its own. Businesses that have rolled out passkeys as part of their security strategy should continue to layer additional protections, such as endpoint security and malware detection, rather than treating passkeys as a silver bullet against account compromise.