Malware Can Steal Google Passkeys Using Pass-ta-key Attacks
Pass-ta-key attacks can let malware abuse Google Password Manager and hijack passkeys stored through Chrome on Windows. The attacks do not crack passkey encryption, but they exploit weaknesses in device registration, recovery, synchronization, and trust checks.
Palo Alto Networks’ Unit 42 discovered three attacks affecting passkeys synchronized through Google Password Manager. Researchers collectively named the techniques Pass-ta-key.
All three attacks require malware to already run on the victim’s Windows computer. However, some techniques work without administrator permissions or further user interaction.
Malware can impersonate a trusted Windows device
The first Pass-ta-key technique lets malware impersonate a Windows device that Google already considers trusted.
The malware abuses Chrome’s TPM-backed device identity key to request a valid authentication response from Google’s cloud authenticator. The process can occur without biometrics, a PIN, user approval, or even unlocking the computer.
Google may then return a signed passkey assertion that the attacker can use to access the targeted account.
Passkey assertions contain a user verification flag that indicates whether the user approved the login through a PIN or biometric check. Websites can block this attack when they require user verification and correctly validate that flag.
Silver Pass-ta-key adds an attacker-controlled key
The second technique, called Silver Pass-ta-key, allows attackers to register their own verification key with Google’s cloud authenticator.
Malware first removes or invalidates Chrome’s existing passkey state, forcing the browser to repeat its device registration process. During registration, the attacker submits a verification key they control.
According to Unit 42, Google’s system did not verify whether the replacement key originated from trusted hardware.
Once Google accepts the malicious key, attackers can use it as proof that the victim approved an authentication request. This technique can bypass services that correctly require PIN or biometric verification.
The attacker can also authenticate later from another device. They no longer need continued access to the original compromised computer.
Golden Pass-ta-key exposes the passkey master secret
The most serious technique, Golden Pass-ta-key, targets the security domain secret used to encrypt all passkeys synchronized through Google Password Manager.
Google temporarily provides this master secret to Chrome during device registration or account recovery. Unit 42 initially found the secret stored in plaintext inside Chrome’s FIDO logs.
Google removed the value from those logs after the researchers disclosed the issue.
However, Unit 42 says the secret still appears temporarily in Chrome’s process memory. Malware can trigger device re-registration and search the browser’s memory for the encryption key.
After extracting the secret, attackers can decrypt synchronized passkey records and access their private keys. They can then transfer those keys to another device and impersonate the victim.
The stolen secret may also decrypt passkeys added to the account later. Researchers reported that Google’s implementation does not currently offer a way to rotate or revoke the security domain secret.
This means attackers could retain access to both existing and future synchronized passkeys after stealing the key.
Passkeys still depend on device security
Unit 42 privately reported the Google Password Manager weaknesses to Google before publishing its research. Google had not publicly confirmed whether it had fully resolved every described technique.
The research shows that passkeys can still become vulnerable when malware compromises the device managing them. Even though Microsoft has been pushing users toward passkeys, passwordless authentication cannot fully protect accounts when attackers control the browser or operating system.
Websites should require user verification and validate the related passkey flag. Credential managers should also confirm that newly registered device keys originate from trusted hardware.
Developers should strengthen device recovery and re-registration processes while limiting how long sensitive encryption keys remain available in browser memory.
Users should continue installing security updates, avoiding suspicious downloads, and protecting their computers against malware. Google has also introduced Selfie Video account recovery with deepfake protections as part of its wider account security efforts.
Device security remains especially important when using public networks. Microsoft recently uncovered a global hotel Wi-Fi malware campaign that targeted travelers through compromised captive portals.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages