Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

Pass-ta-key Research Finds New Weak Links in Synced Passkey Security

Pass-ta-key Research Finds New Weak Links in Synced Passkey Security
Photo by panumas nikhomkhai on Pexels

Researchers have demonstrated three techniques that allow malware on an already compromised Windows computer to abuse passkeys synchronized through Google Password Manager. The attacks do not defeat passkey cryptography, but they expose weaknesses in device trust, recovery workflows, user-verification checks and the handling of key material.

News Date: 2026-08-03

Passkeys are widely promoted as the successor to passwords, but new research shows that passwordless authentication still depends heavily on the integrity of the endpoint and the surrounding implementation.

Palo Alto Networks Unit 42 researchers disclosed three attacks, collectively called Pass-ta-key, affecting Google Password Manager passkeys used through Chrome on Windows systems equipped with a Trusted Platform Module. Each technique requires malware to be running on the victim's computer, so the research does not describe a remote attack against a clean device or a failure of the underlying public-key cryptography.

Three Routes Around Expected Protections

The first technique allows unprivileged malware to impersonate a trusted device and obtain a valid authentication response. Its success can depend on whether the website properly checks the User Verified flag in the WebAuthn response. Researchers successfully demonstrated the issue against eBay before the company corrected its validation process.

The Silver Pass-ta-key variation targets device re-registration. Malware can force Chrome into an onboarding state and register an attacker-controlled verification key. This may let the attacker authenticate from another computer while appearing to have completed the required PIN or biometric verification.

The Golden Pass-ta-key technique is more serious because it targets the master secret used to encrypt synchronized passkeys. Google removed this secret from Chrome's diagnostic logs after disclosure, but the researchers reported that it can still appear temporarily in browser process memory during registration or recovery.

What Security Teams Should Do

  • Require user verification for passkey authentication and validate the resulting flag.
  • Detect unexpected changes to Chrome passkey state and device-registration files.
  • Use endpoint controls that prevent untrusted software from reading browser memory.
  • Investigate unusual recovery prompts or repeated device onboarding events.
  • Keep Chrome, Windows and endpoint security products fully updated.

I believe the central lesson is not that organizations should abandon passkeys. They remain a major improvement over reusable passwords and conventional phishing-sensitive authentication. However, passkeys must not be treated as a substitute for endpoint security.

When malware can manipulate trusted-device signals or observe secrets in memory, the authentication system may faithfully approve a request generated by a compromised machine. In my view, organizations adopting passkeys should combine them with application control, behavioral endpoint detection, hardened recovery procedures and risk-based monitoring of authentication events.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path