Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

0
Medium
Malwaremalware
Published: 08/05/2026 (08/05/2026, 12:48:49 UTC)
Source: SecurityWeek

Description

Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation. The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek .

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 12:56:25 UTC

Technical Analysis

Researchers at Palo Alto Networks demonstrated novel attack techniques against Google’s synced passkey system used in Chrome on Windows. The Pass-ta-key attack involves malware accessing the local synchronization database to identify passkey-protected accounts and associated encrypted credentials. The malware recovers a device identity key and uses Windows cryptographic APIs to generate valid authentication signatures without biometric prompts or device unlocks, tricking Google’s cloud authenticator into issuing valid assertions. The Silver Pass-ta-key variant forces Chrome into device re-registration to register attacker-controlled keys, enabling remote authentication. The Golden Pass-ta-key technique extracts a master secret from Chrome’s memory during re-enrollment, allowing decryption of all synchronized passkeys. These methods bypass protections typically provided by passkeys and passwordless authentication. Google has been informed and has implemented mitigations.

Potential Impact

The attacks enable malware to hijack accounts protected by Google’s synced passkeys without requiring user interaction, privilege escalation, or biometric verification. This compromises the security benefits of passkeys, potentially allowing attackers full account takeover. The Golden Pass-ta-key variant is especially severe, as it allows decryption of all synchronized passkeys for the account, enabling persistent and broad access. These attacks undermine the trust model of passwordless authentication relying on device-bound credentials.

Defensive Guidance

Google has been notified of these attack methods and has rolled out mitigations to address them. Users should ensure their Chrome browsers and related software are updated to the latest versions incorporating these fixes. No additional user action is specified or required at this time according to the vendor disclosure. Organizations should monitor vendor advisories for further updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/new-attack-methods-enable-malware-to-hijack-passkey-protected-accounts/","fetched":true,"fetchedAt":"2026-08-05T12:56:11.378Z","wordCount":1054}

Threat ID: 6a7332ebbf8831d539e82569

Added to database: 08/05/2026, 12:56:11 UTC

Last enriched: 08/05/2026, 12:56:25 UTC

Last updated: 08/05/2026, 23:34:24 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses