Post #4353408
2026-08-03 11:45 UTC
Malware can copy the device key behind Google Chrome passkeys and sign in as you, even with two-factor required, Unit 42 showed.
The hole: sites that never check the "user verified" bit.
Fix: validate that flag server-side.
https://suriq.io/blog/chrome-passkey-malware-account-takeover
#ThreatIntel #Detection #infosec #cybersecurity
Replies (0)
No replies.