The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers at Palo Alto Networks' Unit 42 have disclosed three attack techniques, called Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key, that let malware on an already-compromised Windows PC hijack passkeys stored in Google Chrome's Password Manager without the victim's fingerprint, PIN or knowledge.
- The attacks do not break passkey cryptography but exploit how Chrome stores device keys, re-enrolls devices, and whether websites enforce user-verification checks.
- The strongest path can extract a secret used to decrypt synced passkeys, potentially giving attackers reusable access from their own machines.
- There is no evidence of real-world exploitation yet, and no CVE identifiers, affected Chrome versions, or confirmation that the flaws have been fully fixed.
What to watch next
- Google's response on whether a stolen Security Domain Secret survives a Password Manager PIN change, and any CVE identifiers or fixed Chrome versions it publishes.
- Whether Google adds hardware-attestation checks when accepting replacement user-verification keys during device re-enrollment.
- Whether more websites like eBay close the gap by enforcing the user-verification (UV) flag check, as GitHub already does.
Coverage1
1 report
English national1
All filed from India
Named United States · Chrome · eBay · GitHub · Google · Palo Alto Networks · Unit 42
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
