[REVISION HISTORY]
Passkey authentication security concerns – new variants
Updated 1 time since CLSTR started tracking revisions of this situation.
What changed
2026-08-06 08:41 UTC → 2026-08-07 13:13 UTC ·
added
removed
Passkey authentication security concerns – new variants
In early August 2026, Japanese fintech MoneySquare announced it would roll out a rollout of passkey authentication for customer logins, following guidance from Japan’s Financial Services Agency and the Japan Securities Association. The launch was accompanied by a warning from At the same time, Palo Alto Networks’ Unit 42 about warned that a newly discovered “Pass‑ta‑key” attack that can could bypass passkey logins by exploiting Google Password Manager on Windows PCs that have already been compromised by malware. Google had recently patched a related logging issue, but the researchers said risks remained during device re‑registration. Two days later, later Unit 42 released a detailed technical briefing on describing several variants of the Pass‑ta‑key technique. It described several variants, including The original Pass‑ta‑key uses the device‑identity key to generate a “Golden WebAuthn assertion without the user‑verification flag. A “Silver Pass‑ta‑key” forces Chrome to re‑onboard the device, allowing forged assertions that appear to have passed Windows Hello verification. The “Golden Pass‑ta‑key” extracts the temporary encryption key Chrome uses to protect synchronized passkeys in memory. By stealing this key, malware can retrieve both existing 32‑byte Security Domain Secret (SDS) from Chrome’s diagnostic logs, giving attackers portable private‑key material and newly created passkeys, allowing unauthorized enabling authentication without biometric checks. Google subsequently removed the SDS from those logs, and services such as eBay have updated their implementations to require proper user verification. Unit 42 also reported a related “Vaultjacking” technique described by Japanese firm PhishU, which obtains a Google Password Manager PIN via phishing, joins the security domain, and decrypts all synced passkeys and passwords. The researchers emphasized reiterated that while passkeys are safer than traditional passwords, they are remain vulnerable when the on infected host device is infected, and they urged devices, urging users to keep operating systems and browsers up to date and for service providers to add extra additional verification steps.
Versions
- 2026-08-07 13:13 UTC Passkey authentication security concerns – new variants
- 2026-08-06 08:41 UTC Passkey authentication security concerns
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.