Malware can hijack Google-synced passkeys on Windows

Palo Alto Networks disclosed ‘Pass-ta-key’ attacks that let malware on Windows Chrome hijack Google-synced passkey accounts without user interaction; Silver and Golden escalate access.
Palo Alto Networks researchers disclosed a set of attacks called ‘Pass-ta-key’ that allow malware on Windows machines running Chrome to hijack accounts protected by Google-synced passkeys without user interaction or privilege escalation.
In a typical attack, malware on a compromised PC reads Chrome’s local synchronization database to identify which online accounts use passkeys, along with usernames and encrypted credential material. The malware recovers a device identity key that Chrome stores on disk or holds in memory, then uses Windows cryptographic APIs to sign an authentication challenge from Google’s cloud authenticator.
Because the cloud service receives a valid signature from a registered device, it returns an authentication assertion. The attacker forwards that assertion to the target website to complete a login. The process requires no biometric prompt, device unlock, elevated privileges or explicit user consent.
Palo Alto Networks described two advanced variants. In the ‘Silver’ variant, malware forces Chrome into a device re-registration flow and registers an attacker-controlled user-verification key with the cloud authenticator during a brief window, enabling later authentication from a different device.
In the ‘Golden’ variant, malware extracts a master secret that briefly appears in Chrome’s process memory during re-enrollment. Possession of that secret allows the attacker to decrypt synchronized passkey private keys tied to the user’s account and to decrypt passkeys synced later.
Palo Alto Networks published technical details and wrote that it notified Google. The advisory notes that Google has rolled out mitigations in response. The researchers recommended monitoring and hardening endpoint security to prevent initial malware presence.
The researchers reported no evidence of active exploitation beyond their proof-of-concept testing. Passkeys are a passwordless authentication method based on FIDO and WebAuthn standards; many browsers and platforms sync passkeys to the cloud so users can sign in from multiple devices.







