Security researchers from Palo Alto Networks' Unit 42 have detailed three new attack methods, collectively named "Pass-ta-key," that can compromise passkey-protected accounts managed by Google Password Manager in Chrome on Windows devices. These attacks enable malware, already present on a victim's machine, to bypass the security measures of passkeys without requiring user interaction or elevated privileges.
The "Pass-ta-key" attacks exploit weaknesses in Chrome's handling of device keys and its device re-enrollment process, rather than breaking the underlying cryptography of passkeys. The methods can silently obtain a valid authentication assertion, install an attacker-controlled user-verification key, or extract the 32-byte Security Domain Secret (SDS) used to decrypt synced passkey private keys. The last two paths can provide reusable access from an attacker's environment after the initial endpoint compromise.
Specifically targeting Google's cloud authenticator, the attacks allow malware to sign into a victim's passkey-protected accounts without requiring a fingerprint, PIN, or any on-screen interaction from the user. This demonstrates that while passkeys are designed to be more secure than passwords, their effectiveness can be undermined if the endpoint system where they are managed is already compromised by malware.
Passkeys are a passwordless authentication method using cryptographic keys, considered safer than passwords due to their resistance to phishing, reuse, and guessing. However, these new findings highlight that the security of passkeys is still dependent on the integrity of the device they are stored on. The attacks require malware to be running on the victim's Windows machine, meaning a clean PC using passkeys would not be vulnerable to these specific methods.
This research is distinct from other recent findings, such as those by Dirk-jan Mollema regarding Windows Hello for Business keys, or SpecterOps' work on reusing signed authentication material for Microsoft Entra ID. While all three demonstrate ways to defeat passkey protections without breaking cryptography, the "Pass-ta-key" attacks specifically target Google Password Manager's synced passkey ecosystem.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Google Chrome has introduced Device-Bound Session Credentials (DBSCs) to protect against session cookie theft, a growing method for account takeovers. This feature stores an encryption key in a device's secure hardware, making stolen session cookies unusable on other machines. The integration addresses a vulnerability that emerged as two-factor authentication and passkeys made traditional password-based attacks less effective.
A security researcher demonstrated a method called Pass-ta-key to extract passkeys from Google Password Manager on Windows machines infected with malware. This highlights that passkeys are not universally stored in hardware-based trusted platform modules (TPMs), contrary to a common misconception, which impacts their perceived security.
Three separate research efforts demonstrated new methods to bypass passkey protections by reusing authentication material or exploiting synced passkey systems, rather than cracking the underlying cryptography. These findings highlight vulnerabilities in current passkey implementations, including those from Microsoft and Google, and indicate that passkeys are not universally resistant to all forms of attack, impacting their perceived security benefits.
Entra ID researcher Dirk-jan Mollema demonstrated that malware running on a signed-in Windows session can use Windows Hello for Business keys to authenticate to Microsoft Entra ID, enabling persistent cloud access. This technique allows an attacker to register new devices and obtain Primary Refresh Tokens (PRTs) without requiring administrative privileges or extracting private keys. The issue stems from how Windows Hello for Business handles key operations while a user is signed in, allowing code to request signed authentication data.
Palo Alto Networks researchers have detailed new attack methods, dubbed 'Pass-ta-key', that allow malware to hijack passkey-protected accounts, specifically targeting Google-synced passkeys on Windows machines running Chrome. These methods enable account takeover without requiring privilege escalation or user interaction, undermining the security benefits of passkeys.
New attack classes have been identified that can compromise passwordless authentication systems, specifically targeting Google's synced passkey ecosystem and Cloud Authenticator. These attacks demonstrate how malware can exploit onboarding, recovery, and device trust workflows to take over passkey-protected accounts, bypass user verification, and extract private keys.
Researchers from Unit 42 successfully bypassed Google's Chrome-based passkeys using a new method called "Pass-ta-key," demonstrating vulnerabilities when a Windows machine is already infected with malware. This discovery indicates that while passkeys offer enhanced security, their effectiveness can be compromised at the endpoint if the underlying system is compromised, potentially impacting user authentication security.
Security researchers identified three "Pass-ta-key" attacks that allow malware on compromised Windows devices to hijack Google Password Manager's synced passkeys. These attacks exploit weaknesses in Chrome and Google's cloud authenticator, enabling account takeover and private key extraction without breaking passkey cryptography. This development highlights vulnerabilities in passkey implementation despite their inherent security advantages over passwords.
Researchers detailed three attack paths, named Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, that allow malware on a Windows machine to bypass passkey protections in Chrome's Google Password Manager. These attacks exploit how Chrome stores device keys and re-enrolls devices, enabling silent authentication or extraction of sensitive passkey data, which matters because it demonstrates vulnerabilities in passkey implementations once a system is already compromised.