← All stories
● Covered by 6 sources · 9 reportsMedium impact7 negative2 neutral

New "Pass-ta-key" Attacks Bypass Passkey Protections in Google Password Manager

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Three "Pass-ta-key" attacks target Google Password Manager in Chrome on Windows.
  • Malware on a compromised Windows machine can bypass passkey user verification.
  • Attacks can silently authenticate, install attacker keys, or extract private keys.
  • The methods do not break passkey cryptography but exploit implementation weaknesses.
  • The attacks require prior malware infection on the victim's Windows device.

New Passkey Attack Methods Discovered

Security researchers from Palo Alto Networks' Unit 42 have detailed three new attack methods, collectively named "Pass-ta-key," that can compromise passkey-protected accounts managed by Google Password Manager in Chrome on Windows devices. These attacks enable malware, already present on a victim's machine, to bypass the security measures of passkeys without requiring user interaction or elevated privileges.

How the Attacks Work

The "Pass-ta-key" attacks exploit weaknesses in Chrome's handling of device keys and its device re-enrollment process, rather than breaking the underlying cryptography of passkeys. The methods can silently obtain a valid authentication assertion, install an attacker-controlled user-verification key, or extract the 32-byte Security Domain Secret (SDS) used to decrypt synced passkey private keys. The last two paths can provide reusable access from an attacker's environment after the initial endpoint compromise.

Impact on Google Password Manager

Specifically targeting Google's cloud authenticator, the attacks allow malware to sign into a victim's passkey-protected accounts without requiring a fingerprint, PIN, or any on-screen interaction from the user. This demonstrates that while passkeys are designed to be more secure than passwords, their effectiveness can be undermined if the endpoint system where they are managed is already compromised by malware.

Passkeys and Endpoint Security

Passkeys are a passwordless authentication method using cryptographic keys, considered safer than passwords due to their resistance to phishing, reuse, and guessing. However, these new findings highlight that the security of passkeys is still dependent on the integrity of the device they are stored on. The attacks require malware to be running on the victim's Windows machine, meaning a clean PC using passkeys would not be vulnerable to these specific methods.

Distinction from Other Passkey Research

This research is distinct from other recent findings, such as those by Dirk-jan Mollema regarding Windows Hello for Business keys, or SpecterOps' work on reusing signed authentication material for Microsoft Entra ID. While all three demonstrate ways to defeat passkey protections without breaking cryptography, the "Pass-ta-key" attacks specifically target Google Password Manager's synced passkey ecosystem.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Google Chrome has introduced Device-Bound Session Credentials (DBSCs) to protect against session cookie theft, a growing method for account takeovers. This feature stores an encryption key in a device's secure hardware, making stolen session cookies unusable on other machines. The integration addresses a vulnerability that emerged as two-factor authentication and passkeys made traditional password-based attacks less effective.

A security researcher demonstrated a method called Pass-ta-key to extract passkeys from Google Password Manager on Windows machines infected with malware. This highlights that passkeys are not universally stored in hardware-based trusted platform modules (TPMs), contrary to a common misconception, which impacts their perceived security.

Three separate research efforts demonstrated new methods to bypass passkey protections by reusing authentication material or exploiting synced passkey systems, rather than cracking the underlying cryptography. These findings highlight vulnerabilities in current passkey implementations, including those from Microsoft and Google, and indicate that passkeys are not universally resistant to all forms of attack, impacting their perceived security benefits.

Entra ID researcher Dirk-jan Mollema demonstrated that malware running on a signed-in Windows session can use Windows Hello for Business keys to authenticate to Microsoft Entra ID, enabling persistent cloud access. This technique allows an attacker to register new devices and obtain Primary Refresh Tokens (PRTs) without requiring administrative privileges or extracting private keys. The issue stems from how Windows Hello for Business handles key operations while a user is signed in, allowing code to request signed authentication data.

Palo Alto Networks researchers have detailed new attack methods, dubbed 'Pass-ta-key', that allow malware to hijack passkey-protected accounts, specifically targeting Google-synced passkeys on Windows machines running Chrome. These methods enable account takeover without requiring privilege escalation or user interaction, undermining the security benefits of passkeys.

New attack classes have been identified that can compromise passwordless authentication systems, specifically targeting Google's synced passkey ecosystem and Cloud Authenticator. These attacks demonstrate how malware can exploit onboarding, recovery, and device trust workflows to take over passkey-protected accounts, bypass user verification, and extract private keys.

Researchers from Unit 42 successfully bypassed Google's Chrome-based passkeys using a new method called "Pass-ta-key," demonstrating vulnerabilities when a Windows machine is already infected with malware. This discovery indicates that while passkeys offer enhanced security, their effectiveness can be compromised at the endpoint if the underlying system is compromised, potentially impacting user authentication security.

Security researchers identified three "Pass-ta-key" attacks that allow malware on compromised Windows devices to hijack Google Password Manager's synced passkeys. These attacks exploit weaknesses in Chrome and Google's cloud authenticator, enabling account takeover and private key extraction without breaking passkey cryptography. This development highlights vulnerabilities in passkey implementation despite their inherent security advantages over passwords.

Researchers detailed three attack paths, named Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, that allow malware on a Windows machine to bypass passkey protections in Chrome's Google Password Manager. These attacks exploit how Chrome stores device keys and re-enrolls devices, enabling silent authentication or extraction of sensitive passkey data, which matters because it demonstrates vulnerabilities in passkey implementations once a system is already compromised.