Remix.run Logo
colemannugent an hour ago

It kinda is. If they use Chrome and it's cloud backed password manager, odds are they use GMail. That plus full access to a trusted device (which you have in this scenario) allows you to change their Google account password. Boom, full persistence.

I can think of at least a dozen easier ways to do nefarious things with this level of access that are at least that simple. As an example, faking user attribution would be trivial.

How could Google patch this? If the client is compromised and the attacker can manipulate the local TPM or it's equivalent there's no defense.