Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » New Attacks Target Google Password Manager, Putting Synced Passkeys at Risk

New Attacks Target Google Password Manager, Putting Synced Passkeys at Risk

Last updated:August 4, 2026
Human Written
  • Security researchers identified three Pass-ta-key attacks that let malware abuse Google Password Manager on Windows devices with a TPM.

  • Attackers can impersonate trusted computers, register fake verification keys, or extract the master security domain secret directly from system memory.

  • Websites must validate the User Verified flag and strengthen device recovery rules to protect passkey users from malware compromises.

New Attacks Target Google Password Manager, Putting Synced Passkeys at Risk

Security researchers discovered three new attack methods targeting Google Password Manager on Windows computers. These attacks allow active malware to trick cloud authenticators of Google and steal synced passkeys. Researchers named these novel techniques Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key.

These exploits target weaknesses in device trust and credential syncing rather than breaking core encryption. Modern passkeys use PINs or biometric scans to replace passwords and stop standard phishing scams.

All three methods require malware to run on the target computer first before the malware interacts with background browser processes to hijack user accounts.

Impersonating Trusted Computers to Bypass Login Verification

The first attack technique carries the name Pass-ta-key. Unprivileged malware uses this method to act like a safe, recognized computer. The harmful software accesses the TPM-backed device identity key of Chrome without asking for permission. It signs fake requests and sends them straight to the cloud authenticator of Google. The malware does not need administrator rights or biometric scans from the user. 

Cloud authenticator of Google believes the request comes from a real, trusted computer. The server returns a signed login proof called an assertion. However, this digital proof contains a special User Verified flag inside its code. The flag shows if someone actually scanned a finger or typed a PIN. The attack fails if a target website checks this flag properly.

Researchers tested this trick on popular online platforms like GitHub and eBay. GitHub blocked the fake attempt because its system checked the flag correctly.

Meanwhile, eBay accepted the fake login because its system failed to check that flag. The online shopping store fixed the safety flaw after researchers sent a private warning.

Many online services still fail to inspect this verification flag when processing sign-in requests. This oversight allows malware to log into accounts without triggering local biometric prompts. 

Registering Malicious Verification Keys on External Systems

The second attack technique carries the name Silver Pass-ta-key. Attackers use malware to force Chrome into a complete re-registration process. The software deletes local storage files or breaks current verification tokens on the computer. Chrome then tries to set up device trust with the server again.

Moreover, the cloud authenticator does not check if new keys come from safe hardware. The bad actor attaches an attacker-controlled user-verification key to the user account. Google accepts requests signed with this fake key without asking questions.

The server assumes the user unlocked the device with a PIN or biometrics. Bad actors can then enter accounts that require strict user checks.

As a result, attackers log in from remote computers without touching the victim’s device again. This trick turns single-device infections into long-term account takeovers across multiple websites.

The attacker maintains full access even if the victim closes their browser. The fake key stays registered on Google’s cloud server until someone manually removes it.

Extracting Master Encryption Keys Direct from System Memory

The third method carries the name Golden Pass-ta-key. This technique creates the most severe danger for online users today. Malware steals the master key that protects all synced passkey records. Tech experts call this master key the security domain secret. Google sends this secret to Chrome during device setup or account recovery.

Researchers found Chrome previously wrote this secret into plain-text FIDO logs. Google quickly removed the secret from the visible browser logs after receiving the security report. In addition, the master key still travels to the browser client during sync operations.

The secret sits inside the process memory of Chrome for a short time during setup. Attackers scan system memory patterns to pull out the master key directly.

Bad actors use the stolen master key to decrypt saved passkey records. They recover private keys and transfer them to foreign computers. Therefore, thieves use these stolen private keys to impersonate victims online.

Users cannot reset or rotate this master key inside their Google account settings. The same secret protects current passkeys and future synced records on the account.

Furthermore, security analysts urge credential managers to harden recovery tasks and memory protection. Online services should also enforce strict device checks to keep users safe.

These warnings come as high-profile targets continue to face relentless cyber threats. Defense giant Lockheed Martin is the latest organization hackers claim to have breached, with a $600 million data haul reportedly listed on the dark web.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.