
Passkeys are becoming more popular as a safer alternative to traditional passwords, but some cracks are starting to show after one group successfully bypassed Google’s Chrome-based passkeys using what they call the “Pass-ta-key” attack method.
It’s taken some time, but passkeys have become common across apps and websites. The premise is simple and effective – ditch the password string and set up a biometrically locked signature that only your authenticated devices can use to sign in.
As safe as it’s proven to be, one group of researchers known as Unit 42 found that Google’s Password Manager has a couple of buried flaws one could use to bypass everything that makes a passkey safe from attack.
The report states that several different methods were used to bypass the safety mechanisms we get out of a passkey. By coming into effect at the endpoint, certain websites can be tricked into thinking the user’s Chrome-based passkey is authentic, when it’s been hijacked.
The entire premise has a caveat – the Windows machine in question needs to have already been infected with malware. A clean PC won’t be vulnerable when passkeys are used, but the researchers found malicious software can attack passkeys at the authentication stage, even if they were created on a healthy device.
There were several methods claimed to have been used, all falling under the moniker “Pass-ta-key.” Method one involves taking over a protected account with malware on the device. The identity key is exported to a disk instead of the TPM, which would normally protect the key. The malware then authenticates itself with Google Password Manager without user consent.
The “silver” passkey attack method goes a step further and tricks the password manager into assuming the user has unlocked the device using biometrics. The infected Windows machine stays in a pending condition, where the user verification process doesn’t flag as finished. In that state, the malware can begin registering its own keys, so every future key will be approved.
The “golden” method was found to be the strongest because it leaked the most information. The encryption process, known as the SDS, leaks into a spot in Google Chrome’s log system. Even after Google removed it, information sticks around in Chrome process memory. The malware is able to take that by dumping Chrome’s memory and collecting the database of the user’s synced passkeys.

Unit 42’s last attack method is the most frightening because it means any future passkeys generated through Google Password Manager are easily decrypted by the attacker. The SDS it stole acts as the blueprint and bypass for all future passkeys. Unless a new SDS is generated, the account’s passkeys will be at risk.
The report notes that the first Pass-ta-key method only worked on eBay, because it didn’t validate the flag that states whether the UV process happened at all. Other services were unnamed, but the research group does claim to have reached out to them.
The other attack methods bypass user verification entirely.
The group has reached out to Google to disclose the discovered exploits, and notes that other passkey providers use the same cloud authenticator model.
Passkeys aren’t necessarily any less safe because of the group’s findings. They cut out an entire portion of vulnerabilities that traditional passwords leave on the table. Still, the onboarding and endpoint weaknesses noted in Google Chrome’s process memory are left susceptible to attack, given that malware is present.
FTC: We use income earning auto affiliate links. More.


