Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Unit 42 described three Windows post-compromise attack paths, Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, that let malware abuse Chrome’s Google Password Manager to log into passkey-protected accounts without a visible user prompt. The report says the techniques target Chrome’s device keys, re-enrollment flow, and Security Domain Secret handling on TPM-equipped systems, with sites like GitHub and eBay highlighted in validation and disclosure discussions. #Unit42 #Chrome #GooglePasswordManager #Pass-ta-key #SilverPass-ta-key #GoldenPass-ta-key #GitHub #eBay

Keypoints

  • Malware already on a Windows device is required to start these attacks.
  • Pass-ta-key abuses Chrome’s wrapped device identity key and TPM-backed signing.
  • Silver Pass-ta-key exploits device re-enrollment to register an attacker-controlled verification key.
  • Golden Pass-ta-key targets the 32-byte Security Domain Secret to recover synced passkey private keys.
  • Sites should require userVerification and verify the UV bit instead of trusting the request alone.

Read More: https://thehackernews.com/2026/08/google-password-manager-attacks-could.html