<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys-osrc9u2o0" -->

---
title: New Pass-ta-key attacks let malware hijack Google-synced...
description: Security researchers at Palo Alto Networks&#x27; Unit 42 have disclosed three novel attacks, collectively called &#x27;Pass-ta-key,&#x27; targeting Google Password Manager&#x27;s...
canonical: https://daily.dev/posts/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys-osrc9u2o0
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: New Pass-ta-key attacks let malware hijack Google-synced passkeys | daily.dev
og:description: Security researchers at Palo Alto Networks&#x27; Unit 42 have disclosed three novel attacks, collectively called &#x27;Pass-ta-key,&#x27; targeting Google Password Manager&#x27;s...
og:url: https://daily.dev/posts/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys-osrc9u2o0
og:image: https://api.daily.dev/og/posts/OsRC9u2o0.png
og:image:alt: New Pass-ta-key attacks let malware hijack Google-synced passkeys
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# New Pass-ta-key attacks let malware hijack Google-synced passkeys

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 5 min read · 0 upvotes · 0 comments

## Summary

Security researchers at Palo Alto Networks' Unit 42 have disclosed three novel attacks, collectively called 'Pass-ta-key,' targeting Google Password Manager's synced passkeys on Windows devices with TPM. The attacks require malware to already be running on the victim's machine. The first technique lets unprivileged malware impersonate a trusted device to obtain a valid authentication assertion without biometrics or user interaction. The second, 'Silver Pass-ta-key,' allows attackers to register their own user-verification key with Google's cloud authenticator, bypassing proper user verification checks. The third and most severe, 'Golden Pass-ta-key,' extracts the master key (security domain secret) used to encrypt all synced passkeys from Chrome's process memory, enabling decryption of current and future passkeys. Google removed the secret from Chrome's FIDO logs after disclosure, but it remains accessible in memory. eBay, one affected service, has patched its user-verification validation flaw. Researchers recommend websites properly validate user verification flags and credential managers harden device re-registration and key rotation processes.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys>

---

Tags: [#authentication](https://daily.dev/tags/authentication), [#malware](https://daily.dev/tags/malware), [#passkeys](https://daily.dev/tags/passkeys)

[View this post on daily.dev](https://daily.dev/posts/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys-osrc9u2o0)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"New Pass-ta-key attacks let malware hijack Google-synced passkeys","url":"https://daily.dev/posts/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys-osrc9u2o0","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys-osrc9u2o0"},"datePublished":"2026-08-04T00:01:42.933Z","dateModified":"2026-08-24T07:03:08.692Z","description":"Security researchers at Palo Alto Networks' Unit 42 have disclosed three novel attacks, collectively called 'Pass-ta-key,' targeting Google Password Manager's...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/241376da93e6be1c5732aceab5ef8a76?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/241376da93e6be1c5732aceab5ef8a76?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys-osrc9u2o0","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"authentication,malware,passkeys","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"New Pass-ta-key attacks let malware hijack Google-synced passkeys"}]}
```

