Researchers show Pass-ta-key attacks can hijack Google Password Manager passkeys on compromised Windows PCs

Researchers say malware on an already-infected Windows computer can abuse Google Password Manager’s synced passkeys to sign in to some accounts as the victim. Palo Alto Networks Unit 42 described three techniques—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—targeting Chrome on Windows systems with a Trusted Platform Module (TPM). The attacks exploit Google’s cloud passkey trust, device re-registration, and key-recovery flows rather than breaking passkey cryptography; eBay reportedly fixed one validation issue after disclosure.
Why it matters: Passkeys are meant to reduce phishing and account theft, so methods that let malware reuse or extract them materially weaken a security control many users rely on. Google and relying sites need to harden verification checks, while affected users and admins should treat endpoint malware on passkey-enabled Windows devices as potentially leading directly to account takeover.

Sources

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Eduard Kovacs 2026.08.05 98% relevant
This is the same underlying event: Palo Alto Networks' disclosure of the Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key techniques against Google-synced passkeys. The article adds reporting that Google has been notified and has rolled out some mitigations.
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Lawrence Abrams 2026.08.03 100% relevant
This article appears to be the first tracked report centered on the newly named Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key attack techniques against Google-synced passkeys.
← Back to all stories