Palo Alto Networks Unit 42 uncovered three attacks, collectively called Pass-ta-key, that let malware on compromised Windows devices abuse Google Password Manager synced passkeys to bypass verification and take over accounts. The research also showed how attackers can extract the security domain secret and recover passkey private keys, affecting services such as Google Password Manager, Chrome, GitHub, and eBay. #GooglePasswordManager #Chrome #GitHub #eBay #Unit42 #Pass-ta-key #SilverPass-ta-key #GoldenPass-ta-key
Keypoints
- Unit 42 found three attacks against Google Password Manager on Windows devices with TPM.
- Pass-ta-key can impersonate a trusted device and request a valid passkey assertion.
- Silver Pass-ta-key lets attackers register their own user-verification key during re-registration.
- Golden Pass-ta-key can extract the security domain secret and decrypt synced passkeys.
- Google and affected services were notified, and eBay fixed the user-verification flaw.