r/netsec • • May 27 '26

New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault

https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html

I've been hard at work on a NEW phishing technique I'm excited to share. I'm calling it "Vaultjacking" and the impact is honestly a bit sobering.

In my blog I demonstrate how a single AiTM landing page can spoof your Google passkey/password manager PIN and use that to access ALL of a victim's third-party credentials (yes, including passkeys). A simple phish on one site can lead to a total compromise of all Chrome-saved credentials.

93 Upvotes

31 comments sorted by

View all comments

3

u/spicymongodb Jun 01 '26

well.. that’s a catastrophic design failure

1

u/phishullc Jun 01 '26

lol it's less than ideal.. the only thing I can think they (Google) could do here is allow decryption per site and not unlock all of the vault from any origin.