New Malware and Security Bugs Target Google and Apple Passkeys

New Malware and Security Bugs Target Google and Apple Passkeys

A newly discovered privacy flaw in Apple’s WebKit engine enables malicious websites to capture a user’s IP address even when iCloud Private Relay is actively enabled. This revelation complicates the narrative that moving away from traditional passwords would solve the industry’s most persistent security and privacy challenges. For years, the tech sector has championed passkeys as a cryptographic leap forward, designed to eliminate the risks of phishing and credential stuffing by tying authentication to hardware. However, as the adoption of these passwordless systems reached a critical mass in 2026, the threat landscape naturally shifted to target the underlying frameworks that manage these credentials. Security researchers have now identified sophisticated methods that circumvent the very biometric and hardware-based protections that were supposed to make accounts unhackable. The emergence of these vulnerabilities suggests that while the format of our credentials has changed, the fundamental need for deep defense and user vigilance remains as critical as ever.

Evolution of Exploits: The Rise of Pass-ta-key Malware

The most sophisticated threat identified recently is the Pass-ta-key malware, which specifically targets the Google Password Manager on Windows-based Chrome installations. This malware operates in a tiered system of severity, beginning with the Basic variant that bypasses standard identity verification prompts. By manipulating the local browser environment, the malware allows attackers to access protected accounts without the user ever seeing a request for a PIN or biometric confirmation. Building on this foundation, the Silver tier of the malware goes a step further by spoofing the actual authentication event. It tricks the system into believing that a legitimate owner has manually interacted with the device to authorize a login. This level of deception is particularly dangerous because it leaves no obvious trail for the average user to notice that their security has been compromised. These developments highlight a shift from stealing individual credentials to subverting the local trust mechanisms of the system.

At the peak of this malicious hierarchy lies the Gold Pass-ta-key variant, which represents a catastrophic failure of the localized security model. This specific version targets Google’s master key system during high-stakes events like account recovery or new device registration. Instead of focusing on a single login session, the malware attempts to extract the entire vault of passkeys stored within the Google ecosystem. If successful, an attacker can effectively clone a user’s digital identity, gaining persistent access to every service linked to that primary Google account. This exploit relies on a crucial prerequisite: the target computer must already be infected with specialized malware, typically delivered through seemingly harmless software downloads or third-party applications. This method proves that while passkeys are resilient against remote phishing attacks, they remain vulnerable to local system compromises. The existence of such tools indicates that hackers are investing heavily in exploiting the master keys that hold our digital lives together.

Privacy Vulnerabilities and Strategic Defense: Beyond the Code

While Windows users face credential theft, those within the Apple ecosystem are dealing with a significant erosion of their privacy promises. The WebKit engine vulnerability represents a major setback for the iCloud Private Relay service, which was designed to mask user IP addresses from websites. Under normal circumstances, this relay acts as a buffer, ensuring that the user’s geographic location and network identity remain anonymous. However, the flaw allows malicious websites to sidestep this protection during the specific moment a passkey request is initiated. By triggering a specific sequence of network calls, a site can force the browser to reveal the actual IP address of the device, bypassing the encrypted tunnels entirely. This is more than just a minor glitch; it is a fundamental breakdown of the privacy barrier that Apple has marketed as a core benefit of its hardware. It demonstrates that even when the authentication itself is secure, the metadata surrounding the process can still be harvested by sophisticated actors for tracking.

Moving forward, organizations and individual users should have prioritized the implementation of layered defense strategies to mitigate the risks associated with these new vulnerabilities. For Apple users concerned about IP leaks, the most effective solution involved utilizing a dedicated third-party VPN service that operated independently of the browser’s internal relay system. This added a redundant layer of anonymity that remained unaffected by specific WebKit bugs. Furthermore, maintaining strict control over software installation and avoiding unverified applications from outside official app stores became the primary defense against the tiered Pass-ta-key malware. Developers were encouraged to refine the isolation between browser processes and the secure hardware modules that stored cryptographic keys. By treating the device itself as a potential point of failure, users could have ensured that their passkeys remained a robust defense rather than a single point of failure. These proactive steps allowed the tech community to navigate the growing pains of new authentication standards.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later