Skip to content

Pass-ta-key: New attacks bypass Google’s synced passkeys

In brief: Malware on already-compromised Windows machines can hijack Google’s synced passkeys or extract their private keys via three newly discovered “Pass-ta-key” attacks.

Security researchers have presented three attack techniques that allow malware on already-compromised Windows systems to abuse Google’s synced passkeys. Affected are user verification and the passkey’s own private key.

The attacks, dubbed “Pass-ta-key,” require that a Windows device has already been compromised by malware. Building on this foothold, attackers manage to hijack the passkeys managed by Google Password Manager and synced via the cloud. The researchers demonstrate three distinct approaches: full takeover of user accounts, bypassing user verification, and extracting the private keys of the passkeys themselves.

Passkeys are considered a phishing-resistant alternative to classic passwords, since the private key is actually supposed to remain locally on the device or in a secure hardware component and not be extractable. The synced variant via Google Password Manager makes usage across multiple devices more convenient, but according to the researchers it also creates additional attack surfaces once an endpoint has already been compromised. For CISOs, this means that the introduction of passkeys as a sole line of defense against account takeovers must be put into perspective if endpoint security is not treated with sufficient priority.

The attacks explicitly require prior compromise of the Windows device by malware — this is therefore not a remote attack on unprotected systems, but a post-exploitation technique. This underscores the importance of Endpoint Detection and Response (EDR) and consistent malware prevention as a basic prerequisite for passkey-based authentication to actually deliver its security benefit. Organizations that use synced passkeys via Google Password Manager should take this report as an opportunity to review their endpoint protection and detection capabilities for already-compromised systems.


Source: www.bleepingcomputer.com · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: