Palo Alto Networks disclosed Pass-ta-key attack methods that can let malware hijack Google-synced passkeys and take over protected accounts without user interaction. The researchers also described Silver Pass-ta-key and Golden Pass-ta-key variants, while Google has been notified and mitigations have been rolled out. #Pass-ta-key #SilverPass-ta-key #GoldenPass-ta-key #Google
Keypoints
- Pass-ta-key targets Google-synced passkeys on Windows machines running Chrome.
- Malware can inspect Chromeβs local sync data to identify passkey-protected accounts.
- The attack can use a stored device identity key to generate valid authentication signatures.
- Silver Pass-ta-key can register an attacker-controlled verification key during device re-registration.
- Golden Pass-ta-key can extract a master secret and decrypt synchronized passkey private keys.
Read More: https://www.securityweek.com/new-attack-methods-enable-malware-to-hijack-passkey-protected-accounts/