Malware Can Hijack Google Password Manager Passkeys, Unit 42 Finds
Palo Alto Networks' Unit 42 disclosed three attack techniques, Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key, letting malware already running on a Windows PC take over Google Password Manager passkeys without a fingerprint or PIN. Reported via BleepingComputer and The Ha
Security researchers at Palo Alto Networks' Unit 42 disclosed three new attack techniques against Google Password Manager's synced passkeys in Chrome on Windows. Malware already running on a compromised device can silently obtain a valid login without a fingerprint, PIN, or any prompt appearing on screen. The most severe version, Golden Pass-ta-key, extracts a 32-byte Security Domain Secret from Chrome's process memory, the master key that encrypts every passkey synced to that Google account. In testing, eBay initially accepted a forged login before fixing the issue after disclosure, while GitHub's stricter verification check blocked it. As of August 3, 2026, no CVE has been assigned and Google has not published a way to rotate or revoke an exposed master key. Source: Unit 42 (Palo Alto Networks), BleepingComputer, The Hacker News.