New Pass-Ta-Key Attacks Let Malware Hijack Google-Synced Passkeys
17 Articles
17 Articles
Google Password Manager passkeys could be at risk with new 'Pass-ta-key' attack
Passkeys are becoming more popular as a safer alternative to traditional passwords, but some cracks are starting to show after one group successfully bypassed Google’s Chrome-based passkeys using what they call the “Pass-ta-key” attack method.
Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets
Palo Alto Networks’ Unit 42 detailed three Google passkey exploitsAttacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeysGoogle implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directlySecurity researchers from Palo Alto Networks’ Unit 42 have found three ways to exploit Google’s passkey system and log into people’s PIN…
Think passkeys protect you from hacking and malware? Think again
Credit: Calvin Wankhede / Android Authority TL;DR Security researchers at Palo Alto Networks’ Unit 42 discovered three malware attack paths targeting Google Password Manager’s synced passkeys on Windows PCs. The attacks exploit device trust, onboarding, and recovery mechanisms rather than breaking passkey cryptography itself. The most severe technique, Golden Pass-ta-key, allows attackers to recover the master secret and decrypt all synced pass…
Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
Researchers found three ways malware on an already compromised Windows PC can hijack Google-synced passkeys, bypass user checks, and extract every private key in the vault.
Passkeys Under Siege: How Malware Silently Hijacks Google Password Manager Accounts
Malware already sitting on a Windows PC can slip past every safeguard. No fingerprint scan. No PIN prompt. No flicker on the victim’s screen. It simply signs into passkey-protected services. Palo Alto Networks’ Unit 42 researchers laid out the details in a report released this week. The techniques target Chrome’s implementation of Google Password Manager on systems with a Trusted Platform Module. They expose gaps not in the cryptography itself b…
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









