Researchers disclosed three attack paths—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—that let malware on a compromised Windows endpoint take over accounts protected by Google’s synced passkeys and Google Cloud Authenticator in Chrome. The attacks do not break passkey cryptography; instead, they abuse weaknesses in device trust, onboarding, recovery, and user-verification workflows. Unit 42 reported that even unprivileged malware can enumerate synced passkeys from Chrome’s local sync database, impersonate device identity to obtain valid authentication assertions without user interaction, and in some scenarios bypass or defeat user-verification protections.
The researchers also described more severe escalation paths: an attacker can register an attacker-controlled user-verification key during re-onboarding, and in the highest-impact case, exposure of the security domain secret (SDS) through logs or memory can allow decryption of all synced passkeys. The findings further showed that some relying parties did not properly validate the WebAuthn UV flag, creating an MFA-bypass condition; eBay fixed such an issue after disclosure. The report recommends strict validation of WebAuthn user verification, attestation checks for device-key registration, stronger recovery and re-registration controls, better protection of local passkey data, and preventing client exposure of sensitive key material.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
After Unit 42 reported that Chrome exposed the Google Password Manager security domain secret in plaintext through internal FIDO logs, Google removed the secret from those logs. Unit 42 said the secret was still temporarily accessible in Chrome process memory afterward.
After receiving the researchers’ report, eBay fixed the issue that had allowed passkey login acceptance without proper validation of the WebAuthn UV flag. The fix closed the demonstrated MFA-bypass condition described in the research.
The researchers reported the user-verification validation issue to affected relying parties after identifying the weakness. This disclosure specifically included the issue demonstrated against eBay’s passkey login flow.
The research found that some relying parties accepted passkey authentication without properly validating the WebAuthn User Verified flag, even when user verification was configured as required. GitHub rejected the demonstrated attack when UV was required, while eBay accepted a login before remediation.
Unit 42 researchers documented three attack classes—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—targeting Google’s synced passkey ecosystem and Google Cloud Authenticator on Chrome for Windows with TPM. The attacks enable account takeover or passkey extraction from malware-compromised endpoints without breaking passkey cryptography itself.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcethehackernews.com
Open sourceunit42.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourcew3.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.