Blog

Google Password Manager Under Fire: New Pass-ta-key Attacks Target Your Synced Passkeys

Published August 4th, 2026 by Bayonseo

Passkeys were meant to be the passwordless, phishing-proof, unguessable, and unhackable solution of the future for secure authentication. That promise was just severely damaged.

Three new attack methods, called "Pass-ta-key," have been discovered by security researchers at Palo Alto Networks' Unit 42. These methods enable malware on Windows computers that have already been hacked to take control of Google Password Manager's synchronized passkeys. Attackers can take over accounts, get around user verification, and even retrieve the master encryption key for all of your synced passkeys.

Here's what you need to know.


How Passkeys Work and Where They Fail

Passkeys allow you to access online accounts by using cryptographic key pairs that are stored on your device. Because they are not easily guessed, reused, or phished, they are thought to be safer than passwords. However, as Unit 42's research shows, they don't completely remove the hazards associated with malware that is already present on your device, which is an important disclaimer.

For all three Pass-ta-key assaults to work, the victim's PC must already have malware on it. The cryptography underlying passkeys is not broken by them. Rather, they take advantage of flaws in the way Google's cloud authenticator and Chrome manage device trust, onboarding, recovery, and synchronized credentials.


The Three Attacks: From Bypass to Full Compromise

1. Pass-ta-key (Impersonation)

Unprivileged malware can pose as a trusted device in the most basic assault. Without administrator rights, user involvement, or biometrics, it exploits Chrome's TPM-backed device identification key to ask Google's cloud authenticator for a legitimate authentication answer. The researchers were able to successfully authenticate since eBay failed to correctly check the User Verified flag, whereas GitHub prevented this attack.

2. Silver Pass-ta-key (Verification Bypass)

This more sophisticated attack lets attackers register their own user‑verification key with Google's cloud authenticator. By forcing Chrome to re‑register the compromised device and invalidating its existing verification key, the attacker can slip in their own key because the cloud authenticator doesn't validate whether it originated from trusted hardware. Google then accepts requests signed with the attacker's key as proof that the victim unlocked the device effectively bypassing the user verification requirement entirely.

3. Master Key Theft, or Golden Pass-ta-key

The security domain secret (SDS), the master key used to encrypt all passkeys synchronized through the victim's Google Password Manager account, can be obtained by malware in the most serious attack. Unit 42 discovered that Chrome's internal FIDO logs momentarily revealed this secret in plaintext (a bug Google has subsequently addressed). However, the secret is still transmitted to Chrome and is still available in the process memory of the browser. After being extracted, the attacker can retrieve the private keys from all synchronized passkey records, decrypt them, and then move them to another machine to pretend to be the victim. present and future passkeys are still protected by the same compromised secret because Google's present approach does not allow for the rotation or revocation of this master key.


What This Means for You

The Pass-ta-key attacks serve as a grim reminder that there is no one-size-fits-all security solution. Even though passkeys are still much safer than conventional passwords, they won't shield you if your device has already been compromised.

Currently, the greatest defense is prevention: use strong endpoint protection, keep your devices free of malware, and be careful about what you download and install.


How Bayon Technologies Group Can Help

We at Bayon Technologies Group are aware of how the threat environment is always changing. Although they are effective tools, passkeys and password managers are not a panacea. We assist businesses in creating resilient, multi-layered security plans that consist of:

  • Advanced endpoint security to stop malware infections before they can take advantage of weaknesses like Pass-ta-key.
  • Constant threat monitoring will help you identify and address any questionable activity on your devices.
  • To assist your team in identifying and avoiding malware-delivery routes, provide security awareness training.
  • Plan for incident response to swiftly contain and recover from compromises.

Avoid waiting for your passkeys to be hacked. To create a defense-in-depth plan that safeguards your digital identity, get in touch with Bayon Technologies Group right now.


‹ Back