Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

New Attacks Can Bypass 'Unphishable' Passkey Security

Many third-party Windows password managers now keep passkeys in end-to-end encrypted cloud blobs because malware can access local app data, developers said.

  • On August 3 and August 5, security researchers disclosed new techniques capable of bypassing passkey-based authentication, a standard adopted by more than 400 million websites. The findings target implementation flaws rather than underlying cryptography.
  • Palo Alto Networks' Unit 42 researcher Arie Olshtein identified three attacks, while SpecterOps' Michael Grafnetter discovered more than 20 methods dubbed Pass-the-Passkey. These exploits require malware already running on a compromised Windows device.
  • The most severe technique, Golden Pass-ta-key, extracts a 32-byte secret from Chrome's process memory, allowing attackers to decrypt synced passkeys. Unit 42 documented this path and others bypassing biometric or PIN prompts without triggering user alerts.
  • Microsoft addressed a logging flaw in its July 14 updates, while Google removed a security domain secret from Chrome logs after researcher disclosures. As of August 10, no exploitation of these techniques has been reported in the wild.
  • Experts recommend maintaining endpoint hygiene and keeping Windows updated past July 2026 patches, while organizations should configure servers to bind challenges to user sessions and track signature increments. Monitoring processes for unauthorized WebAuthn invocations provides additional protection.
Insights by Ground AI

12 Articles

"Pass-ta-key": an attack to subtly all the access keys stored in the Google Password Manager app for Windows when the machine is infected by a malwareA computer attack called "Pass-ta-key" allows you to extract the password manager's access keys from Google on Windows. Although "passkeys" (access keys) are perceived as inviolable, they are often stored in synchronized encrypted files rather than in chips...

Researchers discover three methods to steal passwords stored in Google Chrome via malware and access protected accounts without using passwords Passkeys have become the big bet of Google, Microsoft and Apple to replace traditional passwords. They are more comfortable, eliminate the need to memorize keys and, in theory, offer greater protection against data leaks. However, new research has shown that they are not completely immune to attacks eith…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

SempreUPdate broke the news on Monday, August 10, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal