Three Pass-ta-key Attacks Threaten Google Password Manager Passkeys on Windows

Security researchers from Unit 42 disclosed three TPM-based attacks—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—targeting Google Password Manager’s synced passkeys on Windows; the exploits don’t break cryptography but abuse Chrome’s device identity, onboarding, and recovery flows to hijack or recover passkeys. Pass-ta-key impersonates a trusted device to obtain an authentication assertion, though some services verify user verification flags (GitHub blocked it; eBay failed but has since been addressed). Silver Pass-ta-key enables attacker-controlled verification keys during re-registration, letting attackers authenticate from a separate system. Golden Pass-ta-key captures the master key (security domain secret) used to encrypt synced passkeys from memory during re-registration, enabling decryption of passkeys and impersonation across accounts, with no current rotation or revocation. The researchers urge stronger verification, safer recovery/re-registration, and memory-protection of the master key.
- New Pass-ta-key attacks let malware hijack Google-synced passkeys BleepingComputer
- Pass the Passkey: A Novel Attack Surface in Passwordless Authentication Unit 42
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts The Hacker News
- Google Password Manager passkeys could be at risk with new ‘Pass-ta-key’ attack 9to5Google
- Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets TechRadar
Want the full story? Read the original reporting
Read on BleepingComputer