Three Attack Vectors Threaten Chrome Passkeys on Windows

1 min read
Source: The Hacker News
Three Attack Vectors Threaten Chrome Passkeys on Windows
Photo: The Hacker News
TL;DR Summary

Unit 42 details three post-compromise attack paths—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—that let malware on Windows abuse Chrome's Google Password Manager to sign into passkey-protected accounts, re-enroll devices, or extract the 32-byte Security Domain Secret from memory. The flaws do not break cryptography but target how Chrome stores device keys, re-enrolls devices, and checks user verification. No CVEs are listed and there are no confirmed exploits in the wild as of Aug 3, 2026. Mitigations include requiring userVerification, attesting newly enrolled keys, strengthening re-registration/recovery checks, restricting local passkey state access, and avoiding logging sensitive data. It’s unclear if SDS rotation or revocation is possible with current fixes.

Share this article

Reading Insights

Total Reads

1

Unique Readers

2

Time Saved

5 min

vs 6 min read

Condensed

90%

1,030107 words

Want the full story? Read the original article

Read on The Hacker News