Security researchers report three related attacks that allow malware already running on an infected Windows PC to take control of accounts by abusing Google Password Manager–synced passkeys. According to the reporting, the malware can interfere with the passkey flow in a way that bypasses user verification steps and enables account takeover. The researchers also describe the ability for the malware to access and extract passkey private keys from the affected system or the user’s passkey vault associated with Google synchronization.

Both outlets describe the same core finding: the attacks target passkeys that are synced through Google Password Manager, rather than requiring direct cracking of passkeys. The scenario assumes the attacker already has malware on the device, which then leverages weaknesses or misuse paths in how synced passkeys are handled during authentication operations. The reports focus on what the malware can do—hijack passkeys, bypass user checks, and obtain private-key material—while not asserting that passkey security is broadly broken in all environments. The disclosures emphasize that protecting endpoint security remains critical because the attacks require an already compromised Windows system.