TechNewsReel
Live

Malware can hijack Google-synced passkeys via 'Pass-ta-key' flaws

Researchers identify three attack vectors allowing Windows malware to bypass biometrics and steal private passkey data.

TechNewsReel Newsroom · August 4, 2026

Security researchers from Palo Alto Networks' Unit 42 have identified three critical attack vectors, collectively termed 'Pass-ta-key,' that allow malware to hijack passkeys synced via Google Password Manager. These vulnerabilities enable unauthorized account takeovers on compromised Windows devices by bypassing user verification and extracting private cryptographic keys.

The attacks specifically target Chrome on Windows systems equipped with a Trusted Platform Module (TPM). According to Unit 42, the 'Pass-ta-key' attack abuses Chrome's TPM-backed device identity key to sign authentication requests, allowing malware to operate without user interaction or biometric prompts. A more advanced variant, the 'Silver Pass-ta-key' attack, enables malware to register an attacker-controlled user-verification key during a forced device re-registration process, effectively neutralizing PIN and biometric requirements.

The risk of synced passkeys

Passkeys were designed as a phishing-resistant alternative to traditional passwords, utilizing cryptographic key pairs to secure accounts. While device-bound passkeys—such as those stored on physical hardware security keys—offer maximum security, 'synced passkeys' prioritize user convenience. By syncing keys across multiple devices via the cloud, Google Password Manager creates a larger attack surface. If the mechanisms governing device trust or synchronization are flawed, the security benefits of the passkey model are undermined.

The 'Golden' threat

The most severe of the discovered vectors is the 'Golden Pass-ta-key' attack. This method allows attackers to extract the Security Domain Secret (SDS) directly from Chrome's process memory. Once the SDS is obtained, attackers can decrypt all synced passkey private keys. Unit 42 noted that while Google removed this secret from Chrome's logging output following the researchers' report, the SDS is still sent to the client and remains accessible in the process memory.

This vulnerability is particularly critical because it allows the theft of private keys that can be utilized on any system. Furthermore, the lack of a mechanism to rotate or revoke the SDS means that once this master key is compromised, both current and future synced passkeys remain vulnerable.

Industry implications

These findings challenge the industry assumption that passkeys completely eliminate the risk of account takeover on compromised devices. The real-world impact was demonstrated when the attack was successfully tested against eBay; the platform failed to properly validate the User Verified (UV) flag, though eBay has since patched the issue.

Moving forward, the security community will be watching for updates to how Chrome handles the Security Domain Secret and whether Google implements a way to revoke compromised device identities. Until such protections are in place, the 'Golden Pass-ta-key' remains a potent threat for users relying on cloud-synced credentials on Windows.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.