Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-03 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: high ยท affected_sectors: [] ยท au_impact: true

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Summary

Palo Alto Networks Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator. Malware running as an ordinary user on Windows can sign into a victim's passkey-protected accounts without a fingerprint, PIN, or anything appearing on screen.

Attack Paths

Pass-ta-key

Silently obtains a valid authentication assertion without user verification.

Silver Pass-ta-key

Installs an attacker-controlled user-verification key, enabling persistent authentication bypass.

Golden Pass-ta-key

Extracts the 32-byte Security Domain Secret (SDS) used to decrypt all synced passkey private keys, providing full account compromise.

Key Details

  • Date: 2026-08-03
  • Researcher: Palo Alto Networks Unit 42
  • Target: Chrome's Google Password Manager cloud authenticator
  • Platform: Windows (malware running as ordinary user)
  • Privilege required: Ordinary user (no admin required)
  • Source: The Hacker News
  • Reliability: Tier 2/4 โ€” Established cyber journalism

Significance

These attacks carry immediate implications for organisations adopting passkey-based authentication under the ACSC Essential Eight. The ability for non-elevated malware to silently bypass passkey authentication undermines the security model that passkeys were designed to provide over traditional passwords.

Related

  • Cyber Digest 2026 08 04

References