Passkeys are usually considered one of the safest ways to log in to online accounts because they replace passwords with stronger encryption techniques. However, new research has found that under certain conditions, even passkey-protected accounts could be at risk.
Security researchers at Palo Alto Networks’ Unit 42 have discovered three attack techniques that could allow malware on a compromised Windows computer to misuse passkeys stored in Google Password Manager.
The researchers have named these techniques — Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key.
“Each represents a progressively more serious form of post-compromise access, ranging from silently generating a valid login response on the victim’s computer to extracting passkey private keys for use on attacker-controlled systems,” the research team said.
“They exploit how Google Chrome stores device credentials, communicates with Google’s cloud authenticator, re-enrols devices and handles the master secret used to encrypt synchronized passkeys,” they added.
What Is The Flaw?
According to the researchers, malware running on an infected Windows computer can abuse Google’s passkey infrastructure to gain access to accounts protected by passkeys stored in Google Password Manager.
– The first attack allows malware to silently generate a valid login request from the victim’s own computer.
– The second attack is more dangerous because it could trick Google’s systems into accepting an attacker-controlled verification key, allowing future logins without needing the victim’s PC.
– The third and most serious attack could extract a secret encryption key that protects synced passkeys. This can allow attackers to recover passkey credentials and use them on another device.
The researchers found that these attacks do not break the cryptography behind passkeys. Instead, they exploit weaknesses in how Google Chrome, Google Password Manager and cloud synchronisation work together.
“The most severe attack could expose the 32-byte Security Domain Secret, or SDS, that protects the encrypted private keys associated with a Google account’s synchronized passkeys,” said researchers.
In simple words, every attack demonstrated by the researchers requires malware to already be running on the victim’s Windows computer.
This means, hackers cannot simply steal passkeys remotely. They first need to compromise the device through phishing emails, malicious downloads or another malware infection.
The researchers also said they found no evidence that any hacker group or malware campaign is actively using these techniques. They did not link the attacks to any known threat actor.
What Should Users Do?
For most users, passkeys remain far safer than traditional passwords. They still protect against phishing attacks, password leaks and credential stuffing.
However, you should keep their Windows PCs free from malware by installing security updates, avoiding suspicious downloads and using trusted antivirus software.