AUTO-UPDATED

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

Researchers at Palo Alto Networks Unit 42 have identified three novel "Pass-ta-key" attack vectors that allow malware to bypass security protections and hijack Google-synced passkey-protected accounts.

Key Points

  • The "Pass-ta-key" attacks exploit vulnerabilities in Google Chrome’s passkey implementation on Windows devices equipped with Trusted Platform Modules (TPM).
  • Attackers can use unprivileged malware to silently sign authentication requests, bypassing user interaction and biometric verification requirements.
  • The "Silver" attack variant allows attackers to register their own verification keys, enabling persistent, automated account takeover without needing the victim's device.
  • The "Golden" attack variant involves extracting the Security Domain Secret (SDS) from process memory to decrypt and steal all synced passkey private keys.
  • These exploits succeed by targeting gaps in onboarding, recovery workflows, and inconsistent validation of the User Verified (UV) flag by relying parties.

Why it Matters

These findings demonstrate that while passkeys significantly improve security over traditional passwords, they are not immune to sophisticated endpoint-based malware. Organizations and users must treat passkey deployments as one layer of a broader security strategy, emphasizing the need for strict validation of authentication signals and robust endpoint protection.
Paloaltonetworks.com Published by Arie Olshtein
Read original