Pakistan Digital Post

The Pulse of Pakistan's Digital Future

National CERT Warns Pakistan Users of Malware Threat Targeting Chrome Synced Passkeys
News

National CERT Warns Pakistan Users of Malware Threat Targeting Chrome Synced Passkeys

ISLAMABAD: Pakistan’s National Computer Emergency Response Team (National CERT) has issued a high-severity cybersecurity warning over malware capable of stealing Chrome Synced Passkeys from compromised Windows computers, potentially allowing attackers to access Google accounts without the victim’s password or biometric authentication.

The warning highlights a growing security risk for individuals and organisations using Google Chrome’s Synced Passkeys, also known as Cloud Authenticator. According to National CERT, attackers first need to compromise a Windows device with malware before they can target the passkey information stored through Chrome’s synchronisation system.

Malware Can Exploit Trusted Devices

Unlike attacks that attempt to break the cryptography protecting passkeys, the threat focuses on the device and credential-management environment.

Once malicious software gains control of a Windows computer, attackers may be able to access synced passkey material and misuse it to authenticate to associated accounts. This could allow them to bypass the need for conventional passwords, PINs or fingerprints in certain circumstances.

National CERT warned that the threat could affect both individual users and organisations, particularly where Chrome Synced Passkeys are widely used across managed Windows systems.

Attack Could Lead to Google Account Takeover

The potential consequences extend beyond the compromised computer.

If attackers successfully obtain and misuse synced passkey credentials, they could potentially gain unauthorised access to linked Google accounts. National CERT also warned that the technique could undermine some multi-factor authentication protections and allow attackers to maintain access to compromised accounts.

The development is significant because passkeys are widely promoted as a more secure alternative to passwords. The latest warning, however, demonstrates that even stronger authentication technologies depend heavily on the security of the device on which credentials are stored and accessed.

National CERT Advises Users to Update Chrome and Windows

National CERT has urged users to ensure that Google Chrome and Windows are updated with the latest security patches.

Users should also regularly scan their computers for malware and avoid installing software from untrusted or unauthorised sources.

For organisations, the agency recommends restricting unnecessary administrative privileges and preventing the installation of unauthorised software on workplace devices.

Check Google Account Security Settings

Users who suspect that their devices may have been compromised are advised to review their Google account security settings for unfamiliar devices or newly added passkeys.

National CERT recommends removing untrusted devices and checking for suspicious activity, including unexpected sign-ins, new passkey registrations and unusual account-recovery attempts.

The warning comes as cybercriminals increasingly target authentication systems rather than relying solely on traditional password theft.

For Pakistani users and organisations, the message is straightforward: strong authentication cannot compensate for an infected device. Keeping operating systems and browsers updated, limiting software privileges and monitoring account activity remain essential safeguards against increasingly sophisticated malware attacks.

LEAVE A RESPONSE

Your email address will not be published. Required fields are marked *