logo

Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks

ID: 316bcd25-0afb-573d-b9da-3ba1884c910e

STIX ID: report--316bcd25-0afb-573d-b9da-3ba1884c910e

Feed Name: Malwarebytes Blog

Threat Score
65/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

...
...

Researchers have demonstrated that malware can abuse Google Password Manager's passkey synchronization to hijack passkey-protected accounts. They outline three attacks—"Pass‑ta‑key" (malware requests valid passkey assertions without biometric/PIN prompts), "Silver Pass‑ta‑key" (abusing device re-enrollment to register attacker-controlled verification keys), and "Golden Pass‑ta‑key" (extracting Google’s master encryption key to decrypt all synced passkeys). The report urges server-side validation of genuine user verification, stronger device registration/recovery controls, and continued anti-malware hygiene for users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.