The National CERT has warned Windows users about a high-severity threat involving Chrome’s synced passkeys. Malware on an infected computer could allow attackers to steal and misuse passkey data. This could give them access to Google accounts without the victim’s password or biometric authentication.
The warning focuses on Chrome Synced Passkeys, also known as Cloud Authenticator. According to National CERT, attackers can access synced passkey material after gaining control of a Windows device. They may then use it without needing the user’s password, PIN, or fingerprint.
National CERT stressed that the attack does not break the cryptography behind passkeys. Instead, it targets weaknesses in device trust and credential management. The threat only becomes possible after malware has already compromised the Windows endpoint.
The risk affects Windows users who run Google Chrome with Chrome Synced Passkeys enabled. Both individual users and organizations could face account compromise. Attackers may also bypass some multi-factor authentication protections and keep unauthorized access to compromised accounts.
The agency urged users to update Google Chrome and Windows with the latest security patches. Regular malware scans should also be performed on Windows devices. Organizations should restrict administrative access and block unauthorized software installations.
National CERT also advised users to check Google account security settings for unknown devices and passkeys. Any untrusted devices linked to affected accounts should be removed. Organizations should also watch for unusual sign-ins, new passkey registrations, and unexpected account recovery activity.
Security teams should monitor Chrome credential storage and passkey files for unusual access. They should also look for abnormal Chrome activity and information-stealing malware. Any Windows device suspected of infection should be isolated before it is used to access protected accounts.
If a compromise is confirmed, organizations should remove the malware and revoke affected passkeys and trusted devices. They should then register new passkeys, force users to authenticate again, and review recent account activity. Logs should also be preserved for further investigation.
National CERT further advised organizations to compare malware alerts with unusual account activity. This can help identify attackers who may still have access to compromised accounts. Suspected attacks, exploitation attempts, and other unusual activity should be reported through the agency’s incident reporting mechanism.

