12:40
09:00
18:30
16:00
14:25
12:14
12:40
09:00
18:30
16:00
14:25
12:14
12:40
09:00
18:30
16:00
14:25
12:14
12:40
09:00
18:30
16:00
14:25
12:14
Researchers have discovered several ways to bypass protections around passkeys stored in Google Password Manager. The attacks, collectively known as Pass-ta-key, can allow malware to intercept authentication and, in some cases, gain access to a user's entire collection of synced passkeys, 9to5Google reports.
The issue affects Google Password Manager in Chrome on Windows, but the device must already be infected with malware for the attacks to work. Passkeys on an uncompromised computer are not affected.
Researchers identified several attack methods:
The most serious method, dubbed Golden Pass-ta-key, targets a secret stored in Chrome's memory that is used to encrypt synchronized passkeys.
The secret previously could also appear in Chrome logs. Google has removed it from logging, but researchers found that it still remains in the browser's process memory for a period of time. Malware can create a memory dump and use the extracted secret to decrypt a user's synchronized passkeys.
The stolen secret can expose not only existing passkeys but also new ones subsequently created through Google Password Manager. They remain at risk until the service generates a new encryption secret.
Researchers reported the attack methods to Google and noted that other passkey providers use similar cloud-based storage and synchronization models.
The findings do not mean passkeys themselves have become less secure. They still protect against several weaknesses associated with traditional passwords, including credential guessing and conventional phishing attacks.
The newly discovered methods require the Windows device to already be compromised and target Chrome's authentication and passkey synchronization processes.

