Researchers reported that malware on a compromised Windows system can hijack Google-synced passkeys and take over accounts without the victim entering a password, PIN, or biometric factor. Unit 42 said the attack chain, dubbed "Pass-ta-key," abuses weaknesses in Google Cloud Authenticator and Chrome’s handling of device trust, onboarding, and recovery rather than breaking passkey cryptography itself. The report said Chrome stores synced passkey metadata in a local unencrypted database and relies on an exportable identity key that malware can extract through standard Windows cryptography APIs.
The researchers described multiple escalation paths, including forcing Chrome re-onboarding to register an attacker-controlled verification key and extracting the security domain secret (SDS) to decrypt all synced passkeys and maintain persistent access. The issue could enable broad account takeover across services that trust those passkeys, although some providers have already responded; eBay was cited as having patched verification weaknesses after disclosure. A separate report also highlighted that passkey security issues could lead to account takeover, underscoring wider concern over implementation and trust-model gaps in synced passkey ecosystems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
After responsible disclosure, some affected sites including eBay patched verification weaknesses identified by the researchers. These fixes addressed relying-party validation gaps that could otherwise aid account takeover via the disclosed techniques.
Unit 42 reported that malware on a compromised Windows PC can hijack Google-synced passkeys and take over accounts without requiring the victim's password, PIN, or biometric prompt. The research described multiple attack paths exploiting weaknesses in Google Cloud Authenticator and Chrome's handling of device trust, onboarding, and recovery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcecsoonline.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.