Three Pass-ta-key Attacks Threaten Google Password Manager Passkeys on Windows

1 min read
Source: BleepingComputer
Three Pass-ta-key Attacks Threaten Google Password Manager Passkeys on Windows
Photo: BleepingComputer
TL;DR Summary

Security researchers from Unit 42 disclosed three TPM-based attacks—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—targeting Google Password Manager’s synced passkeys on Windows; the exploits don’t break cryptography but abuse Chrome’s device identity, onboarding, and recovery flows to hijack or recover passkeys. Pass-ta-key impersonates a trusted device to obtain an authentication assertion, though some services verify user verification flags (GitHub blocked it; eBay failed but has since been addressed). Silver Pass-ta-key enables attacker-controlled verification keys during re-registration, letting attackers authenticate from a separate system. Golden Pass-ta-key captures the master key (security domain secret) used to encrypt synced passkeys from memory during re-registration, enabling decryption of passkeys and impersonation across accounts, with no current rotation or revocation. The researchers urge stronger verification, safer recovery/re-registration, and memory-protection of the master key.

Share this article

Reading Insights

Total Reads

0

Unique Readers

6

Time Saved

5 min

vs 6 min read

Condensed

89%

1,156127 words

Want the full story? Read the original article

Read on BleepingComputer