Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Summary
Palo Alto Networks Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator. Malware running as an ordinary user on Windows can sign into a victim's passkey-protected accounts without a fingerprint, PIN, or anything appearing on screen.
Attack Paths
Pass-ta-key
Silently obtains a valid authentication assertion without user verification.
Silver Pass-ta-key
Installs an attacker-controlled user-verification key, enabling persistent authentication bypass.
Golden Pass-ta-key
Extracts the 32-byte Security Domain Secret (SDS) used to decrypt all synced passkey private keys, providing full account compromise.
Key Details
- Date: 2026-08-03
- Researcher: Palo Alto Networks Unit 42
- Target: Chrome's Google Password Manager cloud authenticator
- Platform: Windows (malware running as ordinary user)
- Privilege required: Ordinary user (no admin required)
- Source: The Hacker News
- Reliability: Tier 2/4 โ Established cyber journalism
Significance
These attacks carry immediate implications for organisations adopting passkey-based authentication under the ACSC Essential Eight. The ability for non-elevated malware to silently bypass passkey authentication undermines the security model that passkeys were designed to provide over traditional passwords.
Related
- Cyber Digest 2026 08 04