< Back to all clusters
[TECHNOLOGY] · 14 sources

started · updated

Google Passkey Security Flaw Exposes Accounts to Malware

Security researchers at Palo Alto Networks’ Unit 42 disclosed three post‑compromise attack techniques—Pass‑ta‑key, Silver Pass‑ta‑key and Golden Pass‑ta‑key—that let malware on a compromised Windows PC hijack Google Password Manager passkeys. The methods do not break the underlying public‑key cryptography but exploit how Chrome stores and re‑enrolls device identity keys and how the Google Cloud Authenticator validates user verification. Pass‑ta‑key extracts Chrome’s wrapped TPM‑backed identity key to obtain a valid authentication assertion without any fingerprint, PIN or user prompt. Silver Pass‑ta‑key forces a re‑enrollment window to register an attacker‑controlled verification key, bypassing biometric checks. Golden Pass‑ta‑key steals the 32‑byte Security Domain Secret that encrypts all synced passkeys, enabling decryption of past and future credentials. The attacks require malware already present on the machine and affect Chrome on Windows systems equipped with a TPM. Some services, such as GitHub, correctly reject forged assertions, while others (e.g., eBay) were vulnerable until patched after disclosure. Google has been notified and is working on remediation, but no CVE identifiers have been assigned yet.

Entities

Chrome · Google · Google Chrome · Google LLC · Palo Alto Networks Unit 42 · Pillar Security · Trusted Platform Module · Unit 42 · Unit 42 (Palo Alto Networks)

Claims

What the coverage asserts, and how many sources carry each claim.

Sources