TechNewsReel
Live

Malware can hijack Google-synced passkeys via 'Pass-ta-key' vulnerabilities

Palo Alto Networks' Unit 42 discovered three attacks allowing Windows malware to bypass biometrics and extract private keys.

TechNewsReel Newsroom · August 4, 2026

Security researchers from Palo Alto Networks' Unit 42 have identified three novel attack vectors, collectively named "Pass-ta-key," that allow malware on compromised Windows devices to hijack Google-synced passkeys. These vulnerabilities exploit weaknesses in device trust, onboarding, and synchronization rather than breaking the underlying cryptography, potentially leading to full account takeovers.

The attacks target how Chrome and Google's cloud authenticator handle device trust. The basic "Pass-ta-key" attack allows unprivileged malware to impersonate a trusted device, requesting authentication responses from Google's cloud authenticator without requiring user interaction or biometric verification. A more advanced version, the "Silver Pass-ta-key" attack, enables attackers to bypass PIN or biometric requirements entirely by forcing a device re-registration to install their own user-verification key.

The Golden Pass-ta-key

The most severe of the three is the "Golden Pass-ta-key" attack. In this scenario, malware extracts the "security domain secret" (SDS)—a master key—directly from Chrome's process memory. Once this secret is obtained, attackers can decrypt all synced passkey records and recover the private keys. This represents a critical failure in the synchronization chain, as the SDS remains accessible in the process memory even after Google removed it from Chrome's logging output.

Industry Implications

Passkeys were designed as a phishing-resistant alternative to passwords by storing cryptographic keys on local devices. However, Google Password Manager syncs these keys across devices for convenience, introducing new risks if the local environment is compromised. This research demonstrates that while passkeys protect against remote phishing, they do not eliminate the threat of local malware.

Of particular concern is the lack of a rotation or revocation mechanism for the security domain secret. Because this master key is static, a single successful theft can compromise not only current credentials but also any future passkeys synced to the account. This creates a persistent vulnerability for the user until the underlying synchronization architecture is fundamentally changed.

Current Limitations

It is important to note that these are not remote, zero-click exploits. For any of the Pass-ta-key attacks to succeed, malware must already be running on the victim's machine with the permissions of the logged-in user. Users should continue to prioritize endpoint security and malware prevention to mitigate these risks, as the attacks rely on an existing compromise of the Windows host to execute.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.