Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
AI Summary
This article details three novel attack classes against Google's synced passkey ecosystem, collectively termed 'Pass-ta-key', that exploit weaknesses in passwordless authentication implementations. The attacks enable account takeover by malware on a compromised endpoint without user interaction, bypassing user verification requirements and extracting synced passkey private keys. The 'Golden Pass-ta-key' attack is particularly severe, as it allows extraction of the master key (security domain secret) from Chrome's memory during re-onboarding, enabling decryption of all synced passkeys and persistent access. These attacks highlight implementation gaps in relying party validation, device re-registration flows, and exposure of sensitive key material on clients.
AI-extracted · verify before operational use