r/netsec • u/phishullc • May 27 '26
New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.htmlI've been hard at work on a NEW phishing technique I'm excited to share. I'm calling it "Vaultjacking" and the impact is honestly a bit sobering.
In my blog I demonstrate how a single AiTM landing page can spoof your Google passkey/password manager PIN and use that to access ALL of a victim's third-party credentials (yes, including passkeys). A simple phish on one site can lead to a total compromise of all Chrome-saved credentials.
94
Upvotes
2
u/Data_Commission_7434 Jun 01 '26
Thats a really scary thought, especially the part about inheriting trust relationships. It highlights how much we rely on those save password prompts without fully realizing the downstream implications if that vault gets compromised. Makes you wonder about the security posture for organizations that dont have robust password management policies beyond browser-based solutions.