hacker-news · Crawled Aug 3, 2026

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Read original article ↗

AI Summary

Unit 42 researchers identified three post-compromise attack paths—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—targeting Chrome's Google Password Manager on Windows systems with TPM. These attacks allow malware with local access to hijack passkey-protected accounts by exploiting weaknesses in device key handling, user-verification key re-enrollment, and extraction of the 32-byte Security Domain Secret (SDS) from memory. While no active exploitation in the wild is reported, the techniques enable silent authentication, persistent access, and passkey decryption if an attacker gains initial endpoint access.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.