Researchers at Palo Alto Networks Unit 42 have identified three novel "Pass-ta-key" attack vectors that allow malware to bypass security protections and hijack Google-synced passkey-protected accounts.
Key Points
- The "Pass-ta-key" attacks exploit vulnerabilities in Google Chrome’s passkey implementation on Windows devices equipped with Trusted Platform Modules (TPM).
- Attackers can use unprivileged malware to silently sign authentication requests, bypassing user interaction and biometric verification requirements.
- The "Silver" attack variant allows attackers to register their own verification keys, enabling persistent, automated account takeover without needing the victim's device.
- The "Golden" attack variant involves extracting the Security Domain Secret (SDS) from process memory to decrypt and steal all synced passkey private keys.
- These exploits succeed by targeting gaps in onboarding, recovery workflows, and inconsistent validation of the User Verified (UV) flag by relying parties.