Security News

Passkeys Aren't Foolproof: New Malware Attacks Target Google's Synced Passkeys

Security Week · 5 Aug 2026
Key Takeaway Passkeys significantly reduce phishing risk but should be paired with strong endpoint security and malware protection, not treated as a standalone defence.

Passkeys have been widely promoted as a safer, phishing-resistant alternative to passwords, but new research shows they aren't entirely immune to attack. Researchers at Palo Alto Networks have demonstrated methods that allow malware to hijack accounts protected by Google's synced passkey implementation, undermining the assumption that passkeys eliminate account takeover risks altogether.

Synced passkeys are designed for convenience, allowing users to access the same passkey across multiple devices by storing it in the cloud, typically tied to a Google, Apple, or Microsoft account. While this makes passkeys easier to use, it also means that if the underlying account or device is compromised by malware, attackers may find new ways to exploit that access chain to take over accounts that were thought to be well protected.

This research is a reminder that no single security technology is a complete solution on its own. Businesses that have rolled out passkeys as part of their security strategy should continue to layer additional protections, such as endpoint security and malware detection, rather than treating passkeys as a silver bullet against account compromise.

passkeys malware account security authentication Google

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.