THE article discusses vulnerabilities associated with Google's synchronized passkeys, which are designed to replace passwords and enhance security through public-key cryptography. Despite their advantages, recent research reveals that malware can exploit these passkeys via Google Password Manager, highlighting weaknesses in the implementation and synchronization processes. Three types of attacks—Pass‑ta‑key, Silver Pass‑ta‑key, and Golden Pass‑ta‑key—further expose how easily passkeys can be compromised.
Recommendations for improving security include verifying user authentication more rigorously and maintaining good anti-malware practices for users.