Google Chrome Memory Management Flaw Lets Hackers Steal Passkeys to Control Online Accounts
A vulnerability in Google Chrome's memory management allows hackers to extract Passkey credentials directly from memory and take control of victims' online accounts. The attack requires the victim's PC to be already infected with malware. Three attack methods were detailed, including one requiring real-time remote access and another that works without it. None require system privilege escalation or trigger multi-factor authentication. The vulnerability information has been reported to Google.
A security vulnerability in Chrome browser's memory management mechanism allows hackers to directly extract and steal Passkey credentials from memory, thereby taking control of victims' online accounts. A prerequisite for carrying out such attacks is that the victim's PC has already been injected with malware.
There are three attack methods. The first, known as "Pass-ta-key," requires the attacker to have real-time remote access to the target device. By reading synced key records from disk or memory, the attacker simulates the decryption process to deceive the cloud verifier. The second method deletes specific internal Chrome files, forcing the cloud to re-authenticate and issue new keys, allowing the attacker to take over the account without real-time remote control. The third method targets the initial binding stage, inducing the browser to re-run the Passkey registration process and intercepting the master key during the brief moment it appears in plaintext.
None of the above attack methods require system privilege escalation, nor do they trigger multi-factor authentication. The vulnerability information has been reported to Google.
Why this event matters
The event has a measured impact on 1 industry. The strongest current signal is negative for General Software & IT Services, with intensity 40/100 and 60% confidence over a short term horizon.
Impact figures are analytical estimates that combine direction, intensity, confidence and event importance. They are not investment advice.