Report: Passkey Security Issues Could Allow Account Takeover
Unit 42 said malware can abuse Chrome and Google Password Manager to forge passkey checks, and one attack can expose every synced passkey.
- Security Researchers and Unit 42 discovered three Pass-ta-key techniques targeting Google Password Manager on Windows PCs, allowing malware to compromise passkeys by exploiting underlying infrastructure on infected computers.
- Passkeys were marketed as a secure successor to passwords, promising protection against phishing and credential reuse. Google documentation suggests the infrastructure within Chrome on Windows might not be as impenetrable as the company claims.
- The Digital Trends The Golden Pass-ta-key technique uses Chrome's TPM-backed identity to request authentication from Google cloud services. Unit 42 researchers found malware can extract master keys from process memory during device registration or recovery.
- An advanced Silver Pass-ta-key attack forces Chrome to register an attacker-controlled verification key, treating it as proof of biometric verification and granting account access from external devices. Google removed plain-text secrets from internal FIDO logs following researcher disclosure.
- While passkeys remain robust against phishing, this research shows malware on infected computers can bypass infrastructure defenses. Google currently provides no method to rotate or revoke the master secret after compromise, potentially exposing existing and future passkeys.
21 Articles
21 Articles
Report: Passkey security issues could allow account takeover
Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion. They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. “The re…
Google Password Manager passkeys could be at risk with new 'Pass-ta-key' attack
Passkeys are becoming more popular as a safer alternative to traditional passwords, but some cracks are starting to show after one group successfully bypassed Google’s Chrome-based passkeys using what they call the “Pass-ta-key” attack method.
Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets
Palo Alto Networks’ Unit 42 detailed three Google passkey exploitsAttacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeysGoogle implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directlySecurity researchers from Palo Alto Networks’ Unit 42 have found three ways to exploit Google’s passkey system and log into people’s PIN…
Think passkeys protect you from hacking and malware? Think again
Credit: Calvin Wankhede / Android Authority TL;DR Security researchers at Palo Alto Networks’ Unit 42 discovered three malware attack paths targeting Google Password Manager’s synced passkeys on Windows PCs. The attacks exploit device trust, onboarding, and recovery mechanisms rather than breaking passkey cryptography itself. The most severe technique, Golden Pass-ta-key, allows attackers to recover the master secret and decrypt all synced pass…
Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
Researchers found three ways malware on an already compromised Windows PC can hijack Google-synced passkeys, bypass user checks, and extract every private key in the vault.
Coverage Details
Bias Distribution
- 87% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium
















