Three Attack Vectors Threaten Chrome Passkeys on Windows

Unit 42 details three post-compromise attack paths—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—that let malware on Windows abuse Chrome's Google Password Manager to sign into passkey-protected accounts, re-enroll devices, or extract the 32-byte Security Domain Secret from memory. The flaws do not break cryptography but target how Chrome stores device keys, re-enrolls devices, and checks user verification. No CVEs are listed and there are no confirmed exploits in the wild as of Aug 3, 2026. Mitigations include requiring userVerification, attesting newly enrolled keys, strengthening re-registration/recovery checks, restricting local passkey state access, and avoiding logging sensitive data. It’s unclear if SDS rotation or revocation is possible with current fixes.
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts The Hacker News
- Pass the Passkey: A Novel Attack Surface in Passwordless Authentication Unit 42
- Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint CyberSecurityNews
- Google Password Manager Exploit Enables Malware To Hijack Passkey-Protected Accounts LinkedIn
Reading Insights
1
2
5 min
vs 6 min read
90%
1,030 → 107 words
Want the full story? Read the original article
Read on The Hacker News