Skip to content

Attacks on Google Password Manager Put Passkey-Protected Accounts at Risk

Bottom line: Unit 42 demonstrates three attack paths against Chrome’s Google Password Manager that allow malware running under a normal Windows user account to take over passkey-protected accounts without a PIN, fingerprint, or visible interaction.

Security researchers at Unit 42 have identified three attack paths against the cloud authenticator of Chrome’s Google Password Manager that enable malware running under an ordinary user account on Windows to compromise passkey-protected accounts – entirely without a fingerprint, PIN, or any visible interaction on the victim’s screen.

Unit 42, the research team at Palo Alto Networks, has described three attack techniques against the cloud authenticator built into Chrome’s Google Password Manager, naming them Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key. The most severe of the three attacks, Golden Pass-ta-key, targets directly the master key used to protect passkeys within the Google ecosystem. According to the researchers, it is sufficient for malware to run with the privileges of a normal, non-privileged user account on a Windows system in order to subsequently log in as the victim to passkey-protected services – without requiring biometric confirmation, PIN entry, or any visible action on the user’s device whatsoever.

For CISOs, this finding is relevant because passkeys have been promoted in recent years as a replacement for phishing-prone passwords and have already been introduced or planned in many organizations as a building block of a zero-trust or passwordless strategy. The attacks described show that the security guarantee of passkeys depends heavily on how and where the underlying cryptographic key is stored and protected. If this protection is undermined at the operating system level via software, the passkey loses its advantage over classic credentials, since an attacker with local code execution access on the endpoint effectively gains the same control as the legitimate user, without any additional physical factor coming into play.

From an operational standpoint, this means that endpoint hardening and malware prevention must remain an integral part of every passkey strategy for security leaders, particularly on Windows systems that use Google Password Manager as a cloud authenticator. Organizations should check whether and to what extent Google has already provided patches or mitigations for the attack paths described, and review the configuration of their Chrome and Google Workspace environments accordingly. Until reliable vendor information on fixes is available, heightened vigilance regarding endpoint compromise is recommended for users with access to sensitive, passkey-protected accounts.


Source: thehackernews.com · Published August 3, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: