Report: Passkey Security Issues Could Allow Account Takeover
Unit 42 said malware can abuse Chrome and Google Password Manager to forge passkey checks, and one attack can expose every synced passkey.
- Security Researchers and Unit 42 discovered three Pass-ta-key techniques targeting Google Password Manager on Windows PCs, allowing malware to compromise passkeys by exploiting underlying infrastructure on infected computers.
- Passkeys were marketed as a secure successor to passwords, promising protection against phishing and credential reuse. Google documentation suggests the infrastructure within Chrome on Windows might not be as impenetrable as the company claims.
- The Digital Trends The Golden Pass-ta-key technique uses Chrome's TPM-backed identity to request authentication from Google cloud services. Unit 42 researchers found malware can extract master keys from process memory during device registration or recovery.
- An advanced Silver Pass-ta-key attack forces Chrome to register an attacker-controlled verification key, treating it as proof of biometric verification and granting account access from external devices. Google removed plain-text secrets from internal FIDO logs following researcher disclosure.
- While passkeys remain robust against phishing, this research shows malware on infected computers can bypass infrastructure defenses. Google currently provides no method to rotate or revoke the master secret after compromise, potentially exposing existing and future passkeys.
21 Articles
21 Articles
Report: Passkey security issues could allow account takeover
Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion. They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. “The re…
Think passkeys protect you from hacking and malware? Think again
Credit: Calvin Wankhede / Android Authority TL;DR Security researchers at Palo Alto Networks’ Unit 42 discovered three malware attack paths targeting Google Password Manager’s synced passkeys on Windows PCs. The attacks exploit device trust, onboarding, and recovery mechanisms rather than breaking passkey cryptography itself. The most severe technique, Golden Pass-ta-key, allows attackers to recover the master secret and decrypt all synced pass…
Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
Researchers found three ways malware on an already compromised Windows PC can hijack Google-synced passkeys, bypass user checks, and extract every private key in the vault.
Passkeys Under Siege: How Malware Silently Hijacks Google Password Manager Accounts
Malware already sitting on a Windows PC can slip past every safeguard. No fingerprint scan. No PIN prompt. No flicker on the victim’s screen. It simply signs into passkey-protected services. Palo Alto Networks’ Unit 42 researchers laid out the details in a report released this week. The techniques target Chrome’s implementation of Google Password Manager on systems with a Trusted Platform Module. They expose gaps not in the cryptography itself b…
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys.
Coverage Details
Bias Distribution
- 83% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium















