Researchers found a way to steal passkeys straight out of Chrome's memory
TechSpot

Researchers found a way to steal passkeys straight out of Chrome's memory

In brief: Tech companies are rapidly replacing passwords with passkeys because they are easier to use and more secure. However, researchers recently demonstrated that passkeys are not foolproof. The way Google's authenticator stores passkeys in Chrome allows malware to spoof passkey authentication and hijack accounts in multiple ways. Researchers at Unit 42 recently detailed three methods by which malware on a PC can read passkey data stored in Google Chrome. The most severe method completely compromises the victim's Google passkey vault, granting attackers remote access to every account that relies on passkeys. Google, Microsoft, Apple, and many other companies are turning away from passwords, largely because users keep setting ones like "1234." Passkeys, stored on a user's device and decrypted on cloud services via PINs and biometrics, are even considered safer than password generators and managers because there are no passwords for hackers to steal from servers. Using a PIN or biometric is also easier than remembering a password. However, Unit 42 discovered that Google's passkey manager stores enough plaintext information in Chrome's memory for a determined attacker to manipulate the cloud authenticator. All three methods require infecting a PC where the passkeys are stored in Chrome. The first, dubbed Pass-ta-key, requires an attacker to have live, remote access to the target device. By reading synced passkey records from the disk or Chrome's memory, a hacker can mimic Google's decryption method to fool the cloud authenticator and compromise an account. A more dangerous method involves deleting a file within Chrome to force the cloud to re-authenticate the target device. The attacker then issues a new key to gain access to all of the victim's passkey-protected accounts. This route does not require live remote access and allows the attacker to use the compromised passkeys from their machine. Also read: Are Passwords Dead? What Are Passkeys, and Why Everyone's Talking About Them If a hacker learns enough about where Chrome stores passkey data on a target device, they can even intercept a master key and gain complete control over a passkey vault. This requires tricking the browser into repeating the passkey onboarding process and intercepting the master key during a brief period when it appears in Chrome's memory in plaintext. None of the attacks require privilege escalation or trigger multi-factor authentication. Unit 42, which has already informed Google of the vulnerability, advises developers of passkey authenticators to scrutinize unusual passkey usage, tighten security during initial registration, and restrict access to locally stored passkey files.

Comments

No comments yet. Start the discussion.