Your Google Passkeys Aren’t as Safe as You Think

Your Google Passkeys Aren’t as Safe as You Think

Passkeys were supposed to be the end of passwords. No more phishing, no more reused credentials, no more shared secrets getting leaked in data breaches. Google has been pushing them hard—and for good reason. They are more secure than traditional passwords.

But new research from Palo Alto Networks' Unit 42 just dropped a reality check: malware on your Windows PC can hijack your Google-synced passkeys without ever asking for your password, PIN, or fingerprint.

Here's what you need to know.

The "Pass-ta-key" Attacks

Unit 42 discovered three attack techniques, collectively called Pass-ta-key, that target Google Password Manager on Windows devices with a Trusted Platform Module (TPM). The malware doesn't break passkey cryptography itself—it exploits weaknesses in how Chrome handles device trust, onboarding, recovery, and credential syncing.

And here's the kicker: the malware doesn't need admin privileges—it just needs to be running on your machine as you.

Attack 1: Pass-ta-key (Impersonation)

Malware impersonates your trusted device by abusing Chrome's TPM-backed device identity key. It can sign authentication requests without triggering a fingerprint, face scan, or PIN prompt. Some websites accepted these assertions without properly checking the "User Verified" flag. Unit 42 tested this: GitHub rejected it, eBay accepted it—until eBay fixed the issue after disclosure.

Attack 2: Silver Pass-ta-key (Re-enrollment)

This one's scarier. Malware forces Chrome to re-register your device and sneaks in an attacker-controlled verification key. The cloud authenticator accepts it, and now the attacker can generate properly verified login assertions—from their machine, not yours.

Attack 3: Golden Pass-ta-key (Master Key Theft)

The worst of the bunch. The 32-byte Security Domain Secret (SDS)—the master key that encrypts all your synced passkeys—can appear in Chrome's memory during recovery or re-enrollment. If malware captures it, an attacker can decrypt every single synced passkey private key. Google removed an earlier exposure from diagnostic logs after disclosure, but the memory-based path? Still unclear whether it's fully addressed.

What This Means for You

Passkeys are still safer than passwords. They resist phishing, can't be reused, and don't expose shared secrets. But this research proves they don't eliminate all risk—especially if your device is already compromised.

The attacks require malware already on your machine. So the real question is: how's your endpoint security?

What You Can Do Right Now

  1. Run antivirus/antimalware. This isn't optional anymore.
  2. Keep Chrome updated. Google has been notified and is presumably working on fixes.
  3. Enable Google Play Protect if you're on Android—it automatically scans for malware.
  4. Consider Google's Advanced Protection Program—it requires physical security keys for the highest-risk accounts.
  5. If you suspect compromise, remove affected passkeys directly from each online account.
  6. Enable two-step verification (2SV) even if you use passkeys—Google itself recommends this as a backup.

The Bottom Line

Passkeys are a massive step forward. But they're not a silver bullet. The security chain is only as strong as its weakest link—and right now, that link is device compromise.

Keep your machine clean. Stay updated. And don't assume any single security measure makes you invincible.

إرسال تعليق

أحدث أقدم