New Google Password Manager Attacks Can Hijack Synced Passkeys

Three Pass-ta-key attacks show how malware on compromised Windows devices could hijack accounts protected by passkeys synced through Google Password Manager.

執筆者
Kezia Jungco
Kezia Jungco
Aug 4, 2026
3 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Security researchers have uncovered three new attacks that could let malware hijack Google-synced passkeys and take over online accounts from compromised Windows devices.

The techniques target Google Password Manager in Chrome and abuse weaknesses in device trust, user verification, re-registration, credential recovery, and passkey synchronization. 

Depending on the technique, attackers could bypass verification, authenticate from another system, or recover the private keys protecting synced credentials.

Unit 42 did not report observing exploitation in the wild, and the available research does not identify affected Chrome versions or confirm whether every attack path has been fully addressed.

Three attacks target passkey security controls

Palo Alto Networks Unit 42 named the techniques Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key. Each targets a different part of Google Password Manager’s passwordless authentication system, including device identity, user verification, recovery, and credential synchronization.

The basic Pass-ta-key technique allows unprivileged malware to use Chrome’s TPM-backed device identity key to request a valid authentication assertion from Google’s cloud authenticator. The request can occur without administrator privileges, biometrics, a PIN, or visible user interaction.

The technique can fail when a website requires user verification and correctly checks the User Verified flag. Unit 42 successfully tested the attack against eBay because the service did not properly validate the flag, BleepingComputer reported. eBay corrected the issue after the researchers disclosed it.

Silver Pass-ta-key targets device re-registration. Malware can force Chrome to enroll the device again and register an attacker-controlled verification key because Google’s cloud authenticator does not confirm that the new key came from trusted hardware.

Google may then accept signatures from the attacker’s key as proof that the victim completed PIN or biometric verification. The attacker could subsequently authenticate from another system without maintaining access to the original computer.

Advertisement

Golden Pass-ta-key exposes encryption keys

The most severe technique targets the Security Domain Secret used to encrypt passkeys synchronized through Google Password Manager.

Unit 42 initially found the secret exposed in Chrome’s internal FIDO logs. Google removed it from the logs following disclosure, but the researchers said the secret is still sent to Chrome and remains temporarily accessible in the browser’s process memory.

Malware could force device re-registration, locate the secret in memory, and use it to decrypt the victim’s synchronized passkey records. The Hacker News reported that attackers could then extract private keys, transfer them to another system, and impersonate the victim.

Unit 42 also warned that the same secret protects both existing and future synced passkeys. Google’s implementation reportedly does not provide a way to rotate or revoke the secret, potentially leaving future credentials exposed after a compromise.

What security teams should do

Organizations should treat Pass-ta-key as a post-compromise threat. Every described technique requires malware to already be running on the Windows endpoint, making endpoint protection, malware detection, and incident response the first lines of defense.

Websites supporting passkeys should require user verification and correctly validate the User Verified flag in every authentication response. Credential providers should also verify newly registered device keys, strengthen re-enrollment and recovery processes, and prevent encryption secrets from becoming accessible in browser memory.

Security teams should investigate unexpected Google Password Manager recovery prompts, unexplained device re-registration, and passkey logins from unfamiliar systems.

Passkeys remain more resistant to phishing and credential reuse than passwords. The research shows, however, that passwordless authentication still depends on the security of the endpoint, browser, cloud authenticator, and synchronization process surrounding the credential.

Advertisement

Looking for a safer way to manage credentials across your organization? See which six enterprise password managers stand out in 2026.

Kezia Jungco

Kezia Jungco is a staff writer with five years of hands-on experience testing and analyzing generative AI platforms, chatbots, and NLP tools. She writes in-depth coverage for both enterprise and consumer audiences, focusing on artificial intelligence, data analytics, CRM solutions, cloud infrastructure, cybersecurity, and emerging tech trends. Her work appears in TechRepublic, eWEEK, Datamation, TechnologyAdvice, and Selling Signals.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。