unit42 · Crawled Aug 3, 2026

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

2 IoCs
Read original article ↗

AI Summary

This article details three novel attack classes against Google's synced passkey ecosystem, collectively termed 'Pass-ta-key', that exploit weaknesses in passwordless authentication implementations. The attacks enable account takeover by malware on a compromised endpoint without user interaction, bypassing user verification requirements and extracting synced passkey private keys. The 'Golden Pass-ta-key' attack is particularly severe, as it allows extraction of the master key (security domain secret) from Chrome's memory during re-onboarding, enabling decryption of all synced passkeys and persistent access. These attacks highlight implementation gaps in relying party validation, device re-registration flows, and exposure of sensitive key material on clients.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename passkey_enclave_state Details →
Filename WebauthnCredentialSpecifics Details →