Malicious software lurking on compromised Windows PCs now has the capability to hijack Google’s synced passkeys without requiring any user input, including passwords, PINs, or fingerprints. Palo Alto Networks’ Unit 42 uncovered three techniques dubbed Pass-ta-key that exploit vulnerabilities in how Chrome and Google's Cloud Authenticator handle device trust, onboarding, and recovery rather than compromising the underlying passkey cryptography itself. New Passkey Attacks Enable Malware to Gain Full Control of Google Accounts Chrome stores synced passkey metadata in an unencrypted local database, providing malware with a detailed map of every service where users log in using passkeys.
All three techniques require malware already installed on a Windows machine with a Trusted Platform Module (TPM), specifically targeting the Google Password Manager in Chrome, and Arie Olshtein found no evidence of in-the-wild exploitation or attribution to any known threat group. The Golden Pass-ta-key attack (Source: Unit 42) Several teams discovered vulnerabilities in relying parties, which fail to validate the "User Verified" flag during authentication, thus simplifying multi-factor authentication to a single factor. Unit 42 is urging relying parties to implement strict user-verification checks, require attestation for newly enrolled device keys, enhance recovery flows against unexpected re-registration, and keep master key material out of client-side logs and memory.
Users can periodically review registered passkeys through Chrome's settings to identify unfamiliar devices.












