Malware Can Bypass Google Password Manager’s Passkey Defenses to Hijack Accounts

Malware Can Bypass Google Password Manager’s Passkey Defenses to Hijack Accounts

A new attack technique lets malware steal passkey credentials from Google Password Manager, undermining passwordless authentication for website and app accounts.

A recently disclosed attack vector shows that malware running on a compromised system can extract passkey-protected credentials from the Google Password Manager, effectively hijacking accounts even when passkeys are used for authentication. The method targets the local storage and synchronization mechanisms of the password manager, circumventing the cryptographic protections that typically make passkeys resistant to phishing and remote theft.

The attack requires the threat actor to first gain code execution on the victim’s machine, typically through trojans, infostealers, or other malware delivered via malicious downloads, phishing, or software vulnerabilities. Once active, the malware can interact with Google Password Manager’s encrypted database—for example, by dumping memory or exploiting the way the manager handles passkey credentials during autofill operations. Because the manager decrypts passkey material in memory when you authenticate to a site, malware can capture that data before it is used, effectively cloning the passkey.

For website owners and businesses, this development highlights a critical nuance in the passkey security model: while passkeys eliminate server-side password database risks and resist phishing, they remain vulnerable to compromise on the client side if the endpoint is not secure. If an attacker can steal a site’s user passkeys via malware, they can access accounts without needing passwords or multi-factor authentication codes. This means that even passkey-protected logins require robust endpoint protection, regular security audits, and user education to maintain trust.

From an IT infrastructure perspective, hosting providers and administrators must also consider the broader implications. A compromised user device can lead to unauthorized access to managed services, CMS backends, or cloud consoles if those systems rely on passkey-based Google login integrations. Ensuring that your hosting environment enforces additional verification layers—such as conditional access policies, device health checks, or hardware-bound passkeys that cannot be exported—can mitigate the blast radius of such malware attacks. Moreover, keeping all systems patched and using reputable antimalware protection remains essential.

AEU-I’s security-first IT and consulting practice helps businesses assess and strengthen their endpoint and infrastructure security, reducing the risk of malware compromising credential stores like Google Password Manager and ensuring that customer-facing services stay resilient against evolving threats.

Related AEU services

  • AEU Panel Managed hosting control panel
  • AEU-I IT and security consulting