New Attacks Can Bypass 'Unphishable' Passkey Security
Many third-party Windows password managers now keep passkeys in end-to-end encrypted cloud blobs because malware can access local app data, developers said.
- On August 3 and August 5, security researchers disclosed new techniques capable of bypassing passkey-based authentication, a standard adopted by more than 400 million websites. The findings target implementation flaws rather than underlying cryptography.
- Palo Alto Networks' Unit 42 researcher Arie Olshtein identified three attacks, while SpecterOps' Michael Grafnetter discovered more than 20 methods dubbed Pass-the-Passkey. These exploits require malware already running on a compromised Windows device.
- The most severe technique, Golden Pass-ta-key, extracts a 32-byte secret from Chrome's process memory, allowing attackers to decrypt synced passkeys. Unit 42 documented this path and others bypassing biometric or PIN prompts without triggering user alerts.
- Microsoft addressed a logging flaw in its July 14 updates, while Google removed a security domain secret from Chrome logs after researcher disclosures. As of August 10, no exploitation of these techniques has been reported in the wild.
- Experts recommend maintaining endpoint hygiene and keeping Windows updated past July 2026 patches, while organizations should configure servers to bind challenges to user sessions and track signature increments. Monitoring processes for unauthorized WebAuthn invocations provides additional protection.
12 Articles
12 Articles
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Last week a researcher outlined what he said was a “novel attack surface” in passkeys, the new authentication paradigm that offers a more secure alternative over password-based methods. In fact, the attacks demonstrated in the post are neither novel nor unique to passkeys. This distinction is important because the research has generated confusion among end users and security professionals as they assess whether this new mechanism is truly safe t…
"Pass-ta-key": an attack to subtly all the access keys stored in the Google Password Manager app for Windows when the machine is infected by a malwareA computer attack called "Pass-ta-key" allows you to extract the password manager's access keys from Google on Windows. Although "passkeys" (access keys) are perceived as inviolable, they are often stored in synchronized encrypted files rather than in chips...
Researchers discover three methods to steal passwords stored in Google Chrome via malware and access protected accounts without using passwords Passkeys have become the big bet of Google, Microsoft and Apple to replace traditional passwords. They are more comfortable, eliminate the need to memorize keys and, in theory, offer greater protection against data leaks. However, new research has shown that they are not completely immune to attacks eith…
Google Passkeys Targeted by Malware Attack on Windows PCs - News Next Live
Passkeys were introduced as a safer alternative to traditional passwords, mainly because they are designed to resist phishing and do not expose a reusable password during sign in. Google also allows passkeys to be saved and synchronised through Google Password Manager across supported devices. However, security research has highlighted a different risk. If malware gains control of a Windows computer, attackers may be able to abuse the software a…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











