Google Passkeys at Risk? New ‘Pass-ta-key’ Attack Explained! (2026)

Google Password Manager passkeys could be at risk with new 'Pass-ta-key' attack

Passkeys are becoming more popular as a safer alternative to traditional passwords, but some cracks are starting to show after one group successfully bypassed Google’s Chrome-based passkeys using what they call the “Pass-ta-key” attack method. Personally, I think this is a fascinating development that highlights the ongoing arms race between security measures and their potential vulnerabilities. What makes this particularly intriguing is the sophisticated nature of the attack, which involves multiple methods and a deep understanding of the underlying security mechanisms.

The premise of passkeys is simple and effective: ditch the password string and set up a biometrically locked signature that only your authenticated devices can use to sign in. This is a significant improvement over traditional passwords, which are often vulnerable to phishing, keylogging, and other forms of attack. However, as we've seen, even passkeys can have flaws that can be exploited.

The researchers at Unit 42, a cybersecurity firm, found that Google’s Password Manager has a couple of buried flaws that could be used to bypass the safety mechanisms of passkeys. This is a critical finding, as it suggests that even the most secure authentication methods can be compromised if not implemented correctly.

One of the most concerning aspects of the Pass-ta-key attack is that it requires the Windows machine in question to have already been infected with malware. A clean PC won’t be vulnerable when passkeys are used, but the researchers found that malicious software can attack passkeys at the authentication stage, even if they were created on a healthy device. This means that the security of passkeys depends not only on the device itself but also on the overall security posture of the user's system.

The report states that several different methods were used to bypass the safety mechanisms of passkeys. One method involves taking over a protected account with malware on the device. The identity key is exported to a disk instead of the TPM, which would normally protect the key. The malware then authenticates itself with Google Password Manager without user consent.

Another method, dubbed the “silver” passkey attack, tricks the password manager into assuming the user has unlocked the device using biometrics. The infected Windows machine stays in a pending condition, where the user verification process doesn’t flag as finished. In that state, the malware can begin registering its own keys, so every future key will be approved.

The most alarming method, dubbed the “golden” attack, involves the encryption process, known as the SDS, leaking into a spot in Google Chrome’s log system. Even after Google removed it, information sticks around in Chrome process memory. The malware is able to take that by dumping Chrome’s memory and collecting the database of the user’s synced passkeys.

The Unit 42 researchers found that the SDS it stole acts as the blueprint and bypass for all future passkeys. Unless a new SDS is generated, the account’s passkeys will be at risk. This is a significant vulnerability, as it means that any future passkeys generated through Google Password Manager are easily decrypted by the attacker.

The report notes that the first Pass-ta-key method only worked on eBay, because it didn’t validate the flag that states whether the UV process happened at all. Other services were unnamed, but the research group does claim to have reached out to them.

The other attack methods bypass user verification entirely. The group has reached out to Google to disclose the discovered exploits, and notes that other passkey providers use the same cloud authenticator model.

It's important to remember that passkeys aren’t necessarily any less safe because of the group’s findings. They cut out an entire portion of vulnerabilities that traditional passwords leave on the table. However, the onboarding and endpoint weaknesses noted in Google Chrome’s process memory are left susceptible to attack, given that malware is present.

In my opinion, this highlights the need for ongoing vigilance and security updates. As passkeys become more widespread, it's crucial to ensure that they are implemented correctly and that users are educated about the potential risks and how to mitigate them. This includes regular security audits, user education, and the development of more robust security protocols.

What this really suggests is that the security of passkeys depends on a multi-layered approach. While passkeys offer significant advantages over traditional passwords, they are not immune to attack. It's up to us to ensure that they are used securely and that any vulnerabilities are addressed promptly.

Google Passkeys at Risk? New ‘Pass-ta-key’ Attack Explained! (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Catherine Tremblay

Last Updated:

Views: 5884

Rating: 4.7 / 5 (47 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Catherine Tremblay

Birthday: 1999-09-23

Address: Suite 461 73643 Sherril Loaf, Dickinsonland, AZ 47941-2379

Phone: +2678139151039

Job: International Administration Supervisor

Hobby: Dowsing, Snowboarding, Rowing, Beekeeping, Calligraphy, Shooting, Air sports

Introduction: My name is Catherine Tremblay, I am a precious, perfect, tasty, enthusiastic, inexpensive, vast, kind person who loves writing and wants to share my knowledge and understanding with you.