Dossier
Pass-ta-key
Coverage of Pass-ta-key in the Nexus archive.
- Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
Researchers discovered malware can steal Google synchronized passkeys through Google Password Manager, exploiting vulnerabilities in the software despite passkeys being based on public-key cryptography. The 'Pass-ta-key' attacks include scenarios where malware creates unauthorized logins, re-enrolls devices, or decrypts passkeys using a master encryption key.
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware on a Windows machine can bypass security measures to access passkey-protected accounts via vulnerabilities in Chrome's Google Password Manager. Unit 42 identified three attack methods, Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, targeting the password manager's cloud authenticator.