Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 8 sources · 2 days · First seen · Last updated
Passkey authentication security concerns – new variants
Overview
In early August 2026, Japanese fintech MoneySquare announced a rollout of passkey authentication for customer logins, following guidance from Japan’s Financial Services Agency and the Japan Securities Association. At the same time, Palo Alto Networks’ Unit 42 warned that a newly discovered “Pass‑ta‑key” attack could bypass passkey logins by exploiting Google Password Manager on Windows PCs already compromised by malware.
Two days later Unit 42 released a technical briefing describing several variants of the technique. The original Pass‑ta‑key uses the device‑identity key to generate a WebAuthn assertion without the user‑verification flag. A “Silver Pass‑ta‑key” forces Chrome to re‑onboard the device, allowing forged assertions that appear to have passed Windows Hello verification. The “Golden Pass‑ta‑key” extracts the 32‑byte Security Domain Secret (SDS) from Chrome’s diagnostic logs, giving attackers portable private‑key material and enabling authentication without biometric checks. Google subsequently removed the SDS from those logs, and services such as eBay have updated their implementations to require proper user verification.
Unit 42 also reported a related “Vaultjacking” technique described by Japanese firm PhishU, which obtains a Google Password Manager PIN via phishing, joins the security domain, and decrypts all synced passkeys and passwords. The researchers reiterated that while passkeys are safer than passwords, they remain vulnerable on infected host devices, urging users to keep operating systems and browsers up to date and service providers to add additional verification steps.
Entities
Unit 42 · Google · Chrome · windows · Google Password Manager
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 2 SOURCES] Unit 42 identified three attack variants—Pass‑ta‑key, Silver Pass‑ta‑key and Golden Pass‑ta‑key—targeting Google Password Manager synced passkeys on Windows.
- [● 2 SOURCES] All three attacks require malware already present on the victim's Windows PC.
- [● 2 SOURCES] Golden Pass‑ta‑key extracts the 32‑byte Security Domain Secret (SDS) from Chrome diagnostic logs, enabling extraction of private key material.
- [○ 1 SOURCE] Pass‑ta‑key exploits the device‑identity key to generate a WebAuthn authentication assertion without the user‑verification flag.
- [○ 1 SOURCE] Silver Pass‑ta‑key forces Chrome to re‑onboard the device and register a new key, allowing the attacker to produce assertions with the user‑verification flag set.
- [○ 1 SOURCE] eBay initially accepted the forged assertion but later changed its implementation to validate the user‑verification flag.
- [○ 1 SOURCE] Google removed the SDS value from Chrome’s FIDO diagnostic logs after the Unit 42 report.
- [○ 1 SOURCE] The “Vaultjacking” technique described by PhishU obtains a Google Password Manager PIN via phishing to access all synced passkeys and passwords.
Timeline
-
11 days ago
[TECHNOLOGY] 5 sourcesUnit 42 uncovers new attacks on Google Password Manager passkeysUnit 42 discovered three Windows‑based attacks on Google Password Manager’s synced passkeys, exploiting device‑identity keys, Chrome onboarding, and the Security Domain Secret. Google patched log exposure; eBay
-
12 days ago
[TECHNOLOGY] 3 sourcesMoneySquare launches passkey login as security firms warn of Google Password Manager exploitsMoneySquare will roll out passkey login in Japan in August 2026, while researchers disclosed a “Pass‑ta‑key” attack that can bypass Google Password Manager’s passkey authentication, prompting Google to issue a‑
Sources
androidworld.be · atmarkit.itmedia.co.jp · biometricupdate.com · gigazine.net · news.cube-soft.jp · rtvfocuszwolle.nl · techformator.pl · time.news
This summary has been updated 1 time: see revision history