started · updated
Google Passkey Security Flaw Exposes Accounts to Malware
Security researchers at Palo Alto Networks’ Unit 42 disclosed three post‑compromise attack techniques—Pass‑ta‑key, Silver Pass‑ta‑key and Golden Pass‑ta‑key—that let malware on a compromised Windows PC hijack Google Password Manager passkeys. The methods do not break the underlying public‑key cryptography but exploit how Chrome stores and re‑enrolls device identity keys and how the Google Cloud Authenticator validates user verification. Pass‑ta‑key extracts Chrome’s wrapped TPM‑backed identity key to obtain a valid authentication assertion without any fingerprint, PIN or user prompt. Silver Pass‑ta‑key forces a re‑enrollment window to register an attacker‑controlled verification key, bypassing biometric checks. Golden Pass‑ta‑key steals the 32‑byte Security Domain Secret that encrypts all synced passkeys, enabling decryption of past and future credentials. The attacks require malware already present on the machine and affect Chrome on Windows systems equipped with a TPM. Some services, such as GitHub, correctly reject forged assertions, while others (e.g., eBay) were vulnerable until patched after disclosure. Google has been notified and is working on remediation, but no CVE identifiers have been assigned yet.
Entities
Chrome · Google · Google Chrome · Google LLC · Palo Alto Networks Unit 42 · Pillar Security · Trusted Platform Module · Unit 42 · Unit 42 (Palo Alto Networks)
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 4 SOURCES] Silver Pass‑ta‑key forces a re‑enrollment window to register an attacker‑controlled verification key, allowing login without biometric checks. www.technobezz.com · www.archyworldys.com · cybersecuritynews.com · thehackernews.com
- [● 4 SOURCES] Golden Pass‑ta‑key extracts the 32‑byte Security Domain Secret, enabling decryption of all synced passkeys. www.technobezz.com · www.archyworldys.com · cybersecuritynews.com · thehackernews.com
- [● 7 SOURCES] Malware on compromised Windows PCs can hijack Google Password Manager passkeys without user interaction. android-mt.ouest-france.fr · www.technobezz.com · www.archyworldys.com · cybersecuritynews.com · tek.sapo.pt · +2 more
- [● 7 SOURCES] The attacks do not break the underlying cryptography of passkeys. android-mt.ouest-france.fr · www.technobezz.com · www.archyworldys.com · cybersecuritynews.com · tek.sapo.pt · +2 more
- [● 7 SOURCES] Unit 42 identified three attack techniques named Pass‑ta‑key, Silver Pass‑ta‑key and Golden Pass‑ta‑key. android-mt.ouest-france.fr · www.technobezz.com · www.archyworldys.com · cybersecuritynews.com · tek.sapo.pt · +2 more
- [● 2 SOURCES] Some services (e.g., GitHub) correctly reject forged assertions, while others (e.g., eBay) were vulnerable until patched after disclosure. www.technobezz.com · www.archyworldys.com
- [● 2 SOURCES] Google has been notified and is working on remediation; no CVE identifiers have been assigned yet. www.technobezz.com · thehackernews.com
- [● 4 SOURCES] Pass‑ta‑key extracts Chrome’s wrapped device identity key and uses the TPM to sign authentication requests, bypassing user verification. www.technobezz.com · www.archyworldys.com · cybersecuritynews.com · thehackernews.com