< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 8 sources · 2 days · First seen · Last updated

Passkey authentication security concerns – new variants

Overview

In early August 2026, Japanese fintech MoneySquare announced a rollout of passkey authentication for customer logins, following guidance from Japan’s Financial Services Agency and the Japan Securities Association. At the same time, Palo Alto Networks’ Unit 42 warned that a newly discovered “Pass‑ta‑key” attack could bypass passkey logins by exploiting Google Password Manager on Windows PCs already compromised by malware.

Two days later Unit 42 released a technical briefing describing several variants of the technique. The original Pass‑ta‑key uses the device‑identity key to generate a WebAuthn assertion without the user‑verification flag. A “Silver Pass‑ta‑key” forces Chrome to re‑onboard the device, allowing forged assertions that appear to have passed Windows Hello verification. The “Golden Pass‑ta‑key” extracts the 32‑byte Security Domain Secret (SDS) from Chrome’s diagnostic logs, giving attackers portable private‑key material and enabling authentication without biometric checks. Google subsequently removed the SDS from those logs, and services such as eBay have updated their implementations to require proper user verification.

Unit 42 also reported a related “Vaultjacking” technique described by Japanese firm PhishU, which obtains a Google Password Manager PIN via phishing, joins the security domain, and decrypts all synced passkeys and passwords. The researchers reiterated that while passkeys are safer than passwords, they remain vulnerable on infected host devices, urging users to keep operating systems and browsers up to date and service providers to add additional verification steps.

Entities

Unit 42 · Google · Chrome · windows · Google Password Manager

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

Timeline

  1. 11 days ago

    [TECHNOLOGY] 5 sources
    Unit 42 uncovers new attacks on Google Password Manager passkeys

    Unit 42 discovered three Windows‑based attacks on Google Password Manager’s synced passkeys, exploiting device‑identity keys, Chrome onboarding, and the Security Domain Secret. Google patched log exposure; eBay

  2. 12 days ago

    [TECHNOLOGY] 3 sources
    MoneySquare launches passkey login as security firms warn of Google Password Manager exploits

    MoneySquare will roll out passkey login in Japan in August 2026, while researchers disclosed a “Pass‑ta‑key” attack that can bypass Google Password Manager’s passkey authentication, prompting Google to issue a‑

Sources

androidworld.be · atmarkit.itmedia.co.jp · biometricupdate.com · gigazine.net · news.cube-soft.jp · rtvfocuszwolle.nl · techformator.pl · time.news

This summary has been updated 1 time: see revision history