Researchers found a way to steal passkeys straight out of Chrome's memory

Daniel Sims

Posts: 2,568   +77
Staff
In brief: Tech companies are rapidly replacing passwords with passkeys because they are easier to use and more secure. However, researchers recently demonstrated that passkeys are not foolproof. The way Google's authenticator stores passkeys in Chrome allows malware to spoof passkey authentication and hijack accounts in multiple ways.

Researchers at Unit 42 recently detailed three methods by which malware on a PC can read passkey data stored in Google Chrome. The most severe method completely compromises the victim's Google passkey vault, granting attackers remote access to every account that relies on passkeys.

Google, Microsoft, Apple, and many other companies are turning away from passwords, largely because users keep setting ones like "1234." Passkeys, stored on a user's device and decrypted on cloud services via PINs and biometrics, are even considered safer than password generators and managers because there are no passwords for hackers to steal from servers. Using a PIN or biometric is also easier than remembering a password.

However, Unit 42 discovered that Google's passkey manager stores enough plaintext information in Chrome's memory for a determined attacker to manipulate the cloud authenticator. All three methods require infecting a PC where the passkeys are stored in Chrome.

The first, dubbed Pass-ta-key, requires an attacker to have live, remote access to the target device. By reading synced passkey records from the disk or Chrome's memory, a hacker can mimic Google's decryption method to fool the cloud authenticator and compromise an account.

A more dangerous method involves deleting a file within Chrome to force the cloud to re-authenticate the target device. The attacker then issues a new key to gain access to all of the victim's passkey-protected accounts. This route does not require live remote access and allows the attacker to use the compromised passkeys from their machine.

Also read: Are Passwords Dead? What Are Passkeys, and Why Everyone's Talking About Them

If a hacker learns enough about where Chrome stores passkey data on a target device, they can even intercept a master key and gain complete control over a passkey vault. This requires tricking the browser into repeating the passkey onboarding process and intercepting the master key during a brief period when it appears in Chrome's memory in plaintext.

None of the attacks require privilege escalation or trigger multi-factor authentication. Unit 42, which has already informed Google of the vulnerability, advises developers of passkey authenticators to scrutinize unusual passkey usage, tighten security during initial registration, and restrict access to locally stored passkey files.

Permalink to story:

 
No, researchers did not prove Chrome is spyware, and no, they did not prove passkeys are useless. They showed that malware already running on your computer can potentially pull sensitive authentication material from Chrome’s memory. Those PC's are already compromised.

That is a real security flaw and Google should fix it. But if malware is already rummaging through your system memory, your passwords, cookies, session tokens, and plenty of other things may be in trouble too.

So yes, criticize Chrome where it deserves it. But “Google bad, passkeys bad” is not security analysis. It is just forum grunting with a keyboard.
 
No, researchers did not prove Chrome is spyware, and no, they did not prove passkeys are useless.
Yes and no. Chrome is spyware, with how it intercepts so many user data requests and sends all of them to Google―anonymously of course (potentially), but with enough data points and enough time, anyone can be deanonymized―but that's already known. That's not a recent development or news, that's just a fact. Most people don't care, though, because it's "free" and that's all that matters. It's also not the relevant "-ware" in question.

Researchers at Unit 42 recently detailed three methods by which malware on a PC can read passkey data stored in Google Chrome.
As you already alluded to, Chrome is not the problem. Malware is on the computer in this experiment, so it is indeed compromised. But...only Chrome? Did they try this method with any other browser?

Half of the browser market runs on a Chromium-adjacent derivative and they all use the Blink rendering engine. What is unique to the Chrome browser, that doesn't effect any of the others? Or are they all affected by this flaw and Chrome is just the one with the most market share, so it's the one to be the most concerned with?
 
Yes and no. Chrome is spyware, with how it intercepts so many user data requests and sends all of them to Google―anonymously of course (potentially), but with enough data points and enough time, anyone can be deanonymized―but that's already known. That's not a recent development or news, that's just a fact. Most people don't care, though, because it's "free" and that's all that matters. It's also not the relevant "-ware" in question.


As you already alluded to, Chrome is not the problem. Malware is on the computer in this experiment, so it is indeed compromised. But...only Chrome? Did they try this method with any other browser?

Half of the browser market runs on a Chromium-adjacent derivative and they all use the Blink rendering engine. What is unique to the Chrome browser, that doesn't effect any of the others? Or are they all affected by this flaw and Chrome is just the one with the most market share, so it's the one to be the most concerned with?
I actually like the technical question you raised about the other Chromium browsers. That is the part of your post I think moves the conversation somewhere useful.

Where you lose me is the “Chrome is spyware, that’s just a fact” part. We have been talking about exactly this problem throughout this thread...taking something that has legitimate concerns behind it, then repeating the strongest version of the internet narrative as though the argument is already settled.

Chrome collects a lot of data. Google has been sued over privacy and consent issues. Nobody has to pretend Google has a spotless record. But I am not aware of any legal determination that Chrome itself is simply “spyware.” Google also publicly documents much of what Chrome collects and gives users various controls over it.

You can argue that those disclosures are inadequate, that users do not understand them, or that Google collects far too much. Those are legitimate arguments. But that is different from turning “Chrome is spyware” into an established technical or legal fact because we have all read it repeated around the web.

That is really my issue with a lot of these discussions. I would rather we take the interesting question you actually raised and dig into it...why Chrome specifically, and were Edge, Brave, Opera and the others tested too?

That gets us somewhere. Retelling the same internet talking points really doesn’t.
 
Chrome collects a lot of data. Google has been sued over privacy and consent issues. Nobody has to pretend Google has a spotless record. But I am not aware of any legal determination that Chrome itself is simply “spyware.” Google also publicly documents much of what Chrome collects and gives users various controls over it.
It think it is necessary to elaborate that Google Chrome being free is a by-product of early 2000s "internet 'free-ism'". Web browsers, such as Netscape Navigator, used to be paid-for products before Google Chrome came along and gave away its browser. The only reason Internet Explorer was "free", is because it was bundled with Microsoft Windows. Then you have Mozilla Firefox, which has basically been a donation- and partnership-based endeavor (like the Wikipedia project) for the last 20 years. These browser require dedicated development teams to update and/or maintain their code base.

Giving web browsers away for actually-free, no strings attached, is essentially impossible unless we're talking one-off products (which web browsers are not). But, also, we're 20 years removed from "browsers as a paid product". Only digital die-hards and early adopters tolerate paying for a product most people would happily sign away all of their god-given rights to use.
You can argue that those disclosures are inadequate, that users do not understand them, or that Google collects far too much. Those are legitimate arguments. But that is different from turning “Chrome is spyware” into an established technical or legal fact because we have all read it repeated around the web.

That is really my issue with a lot of these discussions. I would rather we take the interesting question you actually raised and dig into it...why Chrome specifically, and were Edge, Brave, Opera and the others tested too?

That gets us somewhere. Retelling the same internet talking points really doesn’t.
Even if Google were brought before a court right now and forced to admit, on the record, that their browser siphons up all of that data in order to fund the development of Chrome (and, y'know, advertising, I doubt it would make a difference. Saying "Google Chrome is spyware" is functionally true and probably legally correct, by the semantic understanding of the term, but also culturally irrelevant. It's not a matter of "the user doesn't understand", it's moreso a matter of "does the user benefit from knowing this?"

In the world of mass-market technology, "convenience is king" and a browser that knows all, does all. We would say that it is invasive and a bad thing, but the average end user would say that it is good because of the data mining. "Less friction to usage, because it already knows everything about me AND it's free? Sign me up!" Hell, if people cared about their digital footprint, the Cambridge Analytica scandal would have ended Facebook and TikTok wouldn't even be a thing. But, they are, because the masses are too concerned with "getting by" to think about the long-term consequences of their actions. Their time horizons are too short.

They are checked-out. They don't care, and that is why Google Chrome has so much market share.
 
It think it is necessary to elaborate that Google Chrome being free is a by-product of early 2000s "internet 'free-ism'". Web browsers, such as Netscape Navigator, used to be paid-for products before Google Chrome came along and gave away its browser. The only reason Internet Explorer was "free", is because it was bundled with Microsoft Windows. Then you have Mozilla Firefox, which has basically been a donation- and partnership-based endeavor (like the Wikipedia project) for the last 20 years. These browser require dedicated development teams to update and/or maintain their code base.

Giving web browsers away for actually-free, no strings attached, is essentially impossible unless we're talking one-off products (which web browsers are not). But, also, we're 20 years removed from "browsers as a paid product". Only digital die-hards and early adopters tolerate paying for a product most people would happily sign away all of their god-given rights to use.

Even if Google were brought before a court right now and forced to admit, on the record, that their browser siphons up all of that data in order to fund the development of Chrome (and, y'know, advertising, I doubt it would make a difference. Saying "Google Chrome is spyware" is functionally true and probably legally correct, by the semantic understanding of the term, but also culturally irrelevant. It's not a matter of "the user doesn't understand", it's moreso a matter of "does the user benefit from knowing this?"

In the world of mass-market technology, "convenience is king" and a browser that knows all, does all. We would say that it is invasive and a bad thing, but the average end user would say that it is good because of the data mining. "Less friction to usage, because it already knows everything about me AND it's free? Sign me up!" Hell, if people cared about their digital footprint, the Cambridge Analytica scandal would have ended Facebook and TikTok wouldn't even be a thing. But, they are, because the masses are too concerned with "getting by" to think about the long-term consequences of their actions. Their time horizons are too short.

They are checked-out. They don't care, and that is why Google Chrome has so much market share.
I actually agree with the broader point you are making about convenience winning over privacy. Most people absolutely will trade data for something that is easy, useful and free.

I do think the browser history is a little more complicated though. Firefox was already being distributed free and open source in 2004, several years before Chrome arrived, so Chrome did not really create the free browser model. The market had already moved pretty far in that direction.

Where I still disagree is calling “Chrome is spyware” functionally or legally settled. You can absolutely call its data collection invasive, excessive, or privacy hostile. But “spyware” is still a loaded label unless we are defining exactly what behavior qualifies.

I also think saying people use Chrome because they are checked out is too simple. Chrome became dominant because it was fast when it launched, worked well with Google services, synced easily across devices, has huge extension support, and later became deeply integrated into Android. Convenience certainly matters, but that is different from people actively liking data mining.

The underlying facts are interesting enough without turning them into the strongest possible internet narrative.
 
How you rate good 2FA. I mean a really complex password, that has to be used in conjunction with another device, usually a mobile phone number? That is still my go to method.

One more general observation. Over the years a considerable portion of Windows patches, and other software are due to flaws or exploits in Remote. Luckily I don't need or use remote and have port #3389 totally blocked.
I guess that's off topic, for another thread perhaps, but seems to me much care is needed when using remote computing.
 
"Beginning September 1, 2026, Microsoft will begin rolling out passkeys as the default authentication experience in Microsoft Entra ID. As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multifactor authentication, they’ll be prompted to register a passkey.

Following this transition, on February 1, 2027, Microsoft will retire Microsoft-provided telecom delivery for SMS and voice authentication and will no longer offer SMS and voice as a native Microsoft Entra capability. Organizations that still require SMS or voice authentication methods will have the option to choose one of our telecom partners through the Microsoft Security Store. Customers will be responsible for any associated telecom-related costs charged by the telecom partners."

Source: https://www.microsoft.com/en-us/sec...the-default-authentication-method-in-entra-id
 
"Beginning September 1, 2026, Microsoft will begin rolling out passkeys as the default authentication experience in Microsoft Entra ID. As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multifactor authentication, they’ll be prompted to register a passkey.

Following this transition, on February 1, 2027, Microsoft will retire Microsoft-provided telecom delivery for SMS and voice authentication and will no longer offer SMS and voice as a native Microsoft Entra capability. Organizations that still require SMS or voice authentication methods will have the option to choose one of our telecom partners through the Microsoft Security Store. Customers will be responsible for any associated telecom-related costs charged by the telecom partners."

Source: https://www.microsoft.com/en-us/sec...the-default-authentication-method-in-entra-id
Well, I wasn't expecting that!

But thanks for the post and the link.
 
Back