Unit 42 has described three attack paths involving Chrome passkeys that could put passkey-protected accounts at risk when Windows malware gains access to a device. The research focuses on Google Password Manager and the way passkey data may be handled or synchronized.

According to the findings, malware running under an ordinary Windows user account could potentially sign in to a victim’s protected services without requiring a fingerprint, PIN or visible approval on the screen. That creates a risk even when an account is secured with passkey-based verification.

The research also examines scenarios in which malware could bypass passkey checks or recover synced private keys after a Windows system has been compromised. These possibilities highlight how device-level malware can undermine protections that are designed to resist conventional password theft.

The report places Chrome, Google Password Manager and passkey synchronization at the center of the issue, while emphasizing the importance of considering local malware access alongside the security of the passkey itself.