logo

New Pass-ta-key attack reveals all the things we didn't know about passkeys

ID: e6a9ff54-2243-53b9-a8c7-369e76acbcb1

STIX ID: report--e6a9ff54-2243-53b9-a8c7-369e76acbcb1

Feed Name: Ars Technica Security (category)

Threat Score
50/100

Date Published: 2026-08-11

Date Updated: 2026-08-11

Author: Dan Goodin

...
...

A researcher demonstrated "Pass-ta-key," a technique where malware on a Windows host can obtain all passkeys stored in Google Password Manager; the report clarifies that this is possible because FIDO2 does not mandate hardware (TPM) storage for passkeys and many platforms keep them in software, which exposes them to local compromise rather than indicating a novel flaw in passkeys themselves.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.