< Back to all clusters
[TECHNOLOGY] · 6 sources

started · updated

Unit 42 uncovers new attacks on Google Password Manager passkeys

Researchers at Palo Alto Networks’ Unit 42 have identified three attack variants—Pass‑ta‑key, Silver Pass‑ta‑key and Golden Pass‑ta‑key—targeting Google Password Manager’s synced passkeys on Windows computers. All variants require malware already present on the victim’s Windows PC and exploit implementation details of Google’s cloud‑authenticator, device‑identity key, Chrome onboarding, and the Security Domain Secret (SDS) used to protect private keys.

Pass‑ta‑key leverages the device‑identity key to generate a WebAuthn authentication assertion without the user‑verification flag. Silver Pass‑ta‑key forces Chrome to re‑onboard the device and register a new key, allowing the attacker to produce assertions that appear to have passed Windows Hello verification. Golden Pass‑ta‑key extracts the 32‑byte SDS from Chrome’s diagnostic logs, enabling the attacker to obtain private key material in a portable form. Google removed the SDS from those logs after the report, and services such as eBay, which initially accepted the forged assertion, have since updated their implementations to require proper user verification.

A related technique dubbed “Vaultjacking” was described by the Japanese firm PhishU. It obtains a Google Password Manager PIN via phishing, then uses the PIN to join the security domain and decrypt all synced passkeys and passwords, allowing the attacker to register new keys and sign in from a new device without the user’s knowledge.

Entities

Chrome · Google Password Manager · Palo Alto Networks · Palo Alto Networks Unit 42 · Security Domain Secret · Unit 42 · Windows · windows

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

  • [○ 1 SOURCE] Silver Pass‑ta‑key forces Chrome to re‑onboard the device and register a new key, allowing the attacker to produce assertions with the user‑verification flag set. www.biometricupdate.com
  • [● 2 SOURCES] Unit 42 identified three attack variants—Pass‑ta‑key, Silver Pass‑ta‑key and Golden Pass‑ta‑key—targeting Google Password Manager synced passkeys on Windows. androidworld.be · www.biometricupdate.com
  • [○ 1 SOURCE] The “Vaultjacking” technique described by PhishU obtains a Google Password Manager PIN via phishing to access all synced passkeys and passwords. atmarkit.itmedia.co.jp
  • [○ 1 SOURCE] Google removed the SDS value from Chrome’s FIDO diagnostic logs after the Unit 42 report. www.biometricupdate.com
  • [○ 1 SOURCE] eBay initially accepted the forged assertion but later changed its implementation to validate the user‑verification flag. www.biometricupdate.com
  • [○ 1 SOURCE] Pass‑ta‑key exploits the device‑identity key to generate a WebAuthn authentication assertion without the user‑verification flag. www.biometricupdate.com
  • [● 2 SOURCES] Golden Pass‑ta‑key extracts the 32‑byte Security Domain Secret (SDS) from Chrome diagnostic logs, enabling extraction of private key material. androidworld.be · www.biometricupdate.com
  • [● 2 SOURCES] All three attacks require malware already present on the victim's Windows PC. androidworld.be · www.biometricupdate.com