logo

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

ID: e380d7dc-f426-505c-812d-1643d8b1c6d1

STIX ID: report--e380d7dc-f426-505c-812d-1643d8b1c6d1

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: Arie Olshtein

...
...

This report demonstrates three novel attack classes against Google’s synced passkey implementation in Chrome on Windows: (1) Pass-ta-key — malware on a compromised endpoint uses the device identity key to silently obtain valid authentication assertions and perform account takeover without user interaction; (2) Silver Pass-ta-key — attackers invalidate and re-register user-verification (UV) keys to obtain assertions with the UV flag set, bypassing biometric/PIN requirements and enabling remote reuse; and (3) Golden Pass-ta-key — attackers extract the security domain secret (SDS) during device re-onboarding to decrypt all synced passkeys, enabling wholesale credential exfiltration and long-term persistence. The report provides technical details of the flows, root causes in onboarding/recovery and logging/memory exposure, and mitigation recommendations for relying parties and credential manager vendors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.