Unit 42
Read post

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

Security researchers from Unit 42 disclose three novel attack classes against Google's synced passkey ecosystem, collectively dubbed 'Pass-ta-key' attacks. The attacks demonstrate how unprivileged malware on a compromised endpoint can exploit implementation gaps to take over passkey-protected accounts without user interaction. The Pass-ta-key attack abuses Chrome's device identity key to silently authenticate as the victim. The Silver Pass-ta-key attack registers an attacker-controlled UV key during the device re-onboarding flow, bypassing user verification entirely and enabling persistent, device-independent account access. The Golden Pass-ta-key attack extracts the security domain secret (SDS) master key from Chrome's process memory, allowing decryption of all synced passkey private keys — with no current mechanism to rotate or revoke the SDS. Key mitigations include enforcing strict UV flag validation on relying parties, validating device key attestation during registration, hardening recovery flows, and preventing sensitive key material from reaching client memory.

    #authentication#malware#passkeys
Aug 03•23m read time•From unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummarySetting the StageStage Zero: ReconnaissanceDevice Identity Impersonation: The Pass-Ta-Key AttackPending Attacker: The Silver Pass-Ta-Key AttackStealing the Master Key: The Golden Pass-Ta-Key AttackMitigationsConclusionAdditional Resources
243 Impressions
Unit 42's image
Unit 42

Unit42 is a cybersecurity research team known for its analysis of cyber threats, malware, and cyber...

63 Followers

•

72 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard