New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation. The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek .
AI Analysis
Technical Summary
Researchers at Palo Alto Networks demonstrated novel attack techniques against Google’s synced passkey system used in Chrome on Windows. The Pass-ta-key attack involves malware accessing the local synchronization database to identify passkey-protected accounts and associated encrypted credentials. The malware recovers a device identity key and uses Windows cryptographic APIs to generate valid authentication signatures without biometric prompts or device unlocks, tricking Google’s cloud authenticator into issuing valid assertions. The Silver Pass-ta-key variant forces Chrome into device re-registration to register attacker-controlled keys, enabling remote authentication. The Golden Pass-ta-key technique extracts a master secret from Chrome’s memory during re-enrollment, allowing decryption of all synchronized passkeys. These methods bypass protections typically provided by passkeys and passwordless authentication. Google has been informed and has implemented mitigations.
Potential Impact
The attacks enable malware to hijack accounts protected by Google’s synced passkeys without requiring user interaction, privilege escalation, or biometric verification. This compromises the security benefits of passkeys, potentially allowing attackers full account takeover. The Golden Pass-ta-key variant is especially severe, as it allows decryption of all synchronized passkeys for the account, enabling persistent and broad access. These attacks undermine the trust model of passwordless authentication relying on device-bound credentials.
Mitigation Recommendations
Google has been notified of these attack methods and has rolled out mitigations to address them. Users should ensure their Chrome browsers and related software are updated to the latest versions incorporating these fixes. No additional user action is specified or required at this time according to the vendor disclosure. Organizations should monitor vendor advisories for further updates.
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Description
Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation. The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Researchers at Palo Alto Networks demonstrated novel attack techniques against Google’s synced passkey system used in Chrome on Windows. The Pass-ta-key attack involves malware accessing the local synchronization database to identify passkey-protected accounts and associated encrypted credentials. The malware recovers a device identity key and uses Windows cryptographic APIs to generate valid authentication signatures without biometric prompts or device unlocks, tricking Google’s cloud authenticator into issuing valid assertions. The Silver Pass-ta-key variant forces Chrome into device re-registration to register attacker-controlled keys, enabling remote authentication. The Golden Pass-ta-key technique extracts a master secret from Chrome’s memory during re-enrollment, allowing decryption of all synchronized passkeys. These methods bypass protections typically provided by passkeys and passwordless authentication. Google has been informed and has implemented mitigations.
Potential Impact
The attacks enable malware to hijack accounts protected by Google’s synced passkeys without requiring user interaction, privilege escalation, or biometric verification. This compromises the security benefits of passkeys, potentially allowing attackers full account takeover. The Golden Pass-ta-key variant is especially severe, as it allows decryption of all synchronized passkeys for the account, enabling persistent and broad access. These attacks undermine the trust model of passwordless authentication relying on device-bound credentials.
Defensive Guidance
Google has been notified of these attack methods and has rolled out mitigations to address them. Users should ensure their Chrome browsers and related software are updated to the latest versions incorporating these fixes. No additional user action is specified or required at this time according to the vendor disclosure. Organizations should monitor vendor advisories for further updates.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/new-attack-methods-enable-malware-to-hijack-passkey-protected-accounts/","fetched":true,"fetchedAt":"2026-08-05T12:56:11.378Z","wordCount":1054}
Threat ID: 6a7332ebbf8831d539e82569
Added to database: 08/05/2026, 12:56:11 UTC
Last enriched: 08/05/2026, 12:56:25 UTC
Last updated: 08/05/2026, 23:34:24 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.