TechNewsReel
Live

Pass-ta-key Attack Hijacks Google-Synced Passkeys on Windows

Researchers find malware can steal synced credentials by abusing Google Password Manager's implementation on Windows endpoints.

TechNewsReel Newsroom · August 11, 2026

Security researchers from Palo Alto Networks' Unit 42 have uncovered a suite of attacks, dubbed "Pass-ta-key," that allow malware on Windows devices to hijack passkeys synced via Google Password Manager (GPM). The discovery reveals a significant vulnerability in how GPM handles synced credentials on Windows, potentially allowing attackers to bypass biometric prompts or PINs to gain unauthorized account access.

The research identifies three distinct attack variants. The primary "Pass-ta-key" method focuses on account takeover, while "Silver Pass-ta-key" enables device re-enrollment or the registration of attacker-controlled keys. The most severe version, "Golden Pass-ta-key," targets the 32-byte Security Domain Secret to recover synced private keys. In one specific instance of the Golden Pass-ta-key variant, the infected Windows machine masquerades as an iPhone to trigger GPM's synchronization and transfer capabilities, effectively tricking the system into releasing sensitive data.

The Implementation Gap

Passkeys are intended to replace passwords with cryptographic key pairs, which are ideally stored in a device's hardware-backed Trusted Platform Module (TPM) or Secure Enclave. To provide user convenience, providers like Google store encrypted versions of these keys in the cloud to enable syncing across multiple devices.

However, the Pass-ta-key attacks do not break the underlying FIDO2 cryptography. Instead, they abuse the specific implementation of synced passkeys and the permissive application privilege model inherent to Windows. Unlike macOS or iOS, Windows applications often run with broad user privileges, which makes it significantly easier for malware to access the data of other applications if they are not strictly sandboxed. This architectural gap allows malware to intercept the synchronization process and extract keys that were meant to be protected.

The Convenience Trade-off

This discovery highlights a critical tension between user convenience and hardware-level security. While passkeys are highly effective at eliminating phishing—since there is no password for a user to accidentally reveal—they do not provide a silver bullet against a compromised endpoint. If malware gains a foothold on a Windows machine, it can abuse the synchronization mechanisms of a password manager to steal credentials without any user interaction.

As Dan Goodin, Senior Security Editor at Ars Technica, noted, the stakes of this attack are comparable to any scenario where an infected Windows machine is fully authenticated into other sensitive applications. The vulnerability is less about the protocol and more about the environment in which the manager operates.

What to Watch

Moving forward, the industry must address the risks associated with cloud-synced credentials versus hardware-bound keys. While Google and other providers continue to refine their synchronization logic, the Pass-ta-key research serves as a reminder that software-based synchronization introduces a new attack surface that hardware-only keys avoid. Users and enterprises should monitor for updates to GPM and consider the security implications of syncing sensitive credentials across platforms with varying privilege models.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.