Three Pass-ta-key Attacks Threaten Google Password Manager Passkeys on Windows

Security researchers from Unit 42 disclosed three TPM-based attacks—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—targeting Google Password Manager’s synced passkeys on Windows; the exploits don’t break cryptography but abuse Chrome’s device identity, onboarding, and recovery flows to hijack or recover passkeys. Pass-ta-key impersonates a trusted device to obtain an authentication assertion, though some services verify user verification flags (GitHub blocked it; eBay failed but has since been addressed). Silver Pass-ta-key enables attacker-controlled verification keys during re-registration, letting attackers authenticate from a separate system. Golden Pass-ta-key captures the master key (security domain secret) used to encrypt synced passkeys from memory during re-registration, enabling decryption of passkeys and impersonation across accounts, with no current rotation or revocation. The researchers urge stronger verification, safer recovery/re-registration, and memory-protection of the master key.
- New Pass-ta-key attacks let malware hijack Google-synced passkeys BleepingComputer
- Pass the Passkey: A Novel Attack Surface in Passwordless Authentication Unit 42
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts The Hacker News
- Google Password Manager passkeys could be at risk with new ‘Pass-ta-key’ attack 9to5Google
- Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets TechRadar
Reading Insights
0
6
5 min
vs 6 min read
89%
1,156 → 127 words
Want the full story? Read the original article
Read on BleepingComputer