구글 비밀번호 관리자 공격이 패스키 보호 계정을 위험에 빠뜨릴 수 있음.
구글 비밀번호 관리자의 취약점을 통해 악성 소프트웨어가 사용자의 패스키 보호 계정에 접근할 수 있는 방법이 공개되었습니다. Unit 42는 세 가지 공격 경로를 설명했으며, 이는 사용자의 화면에서 어떠한 사용자 입력 없이도 이루어질 수 있습니다. 이러한 공격은 특히 마스터 키를 목표로 하는 강력한 공격을 포함합니다.
Google Password Manager vulnerabilities could let malware access passkey-protected accounts.
The vulnerabilities in Google's Password Manager could allow malware operating as a regular user to access passkey-protected accounts without any user input on the victim's screen. Unit 42 detailed three attack vectors against the cloud authenticator, highlighting serious risks, especially targeting the master key. This poses significant security concerns for users relying on passkeys for account protection.