Alanna
River

Pass-ta-key Attacks: Why Endpoint Security Still Matters in a Passkey World

Alanna River

Aug 4, 2026

3 min read

Pass-ta-key

The "What Happened"

  • BleepingComputer reported that Unit 42 disclosed three attacks collectively called Pass-ta-key against Google Password Manager synced passkeys on Chrome for Windows.
  • The attacks require malware to already be running on the victim’s Windows device and do not break passkey cryptography.
  • The first Pass-ta-key technique lets unprivileged malware abuse Windows Cryptography API: Next Generation (CNG) calls to interact with Chrome’s wrapped TPM key blob and request a valid authentication assertion from Google’s cloud authenticator without user interaction, biometrics, or a PIN.
  • The Silver Pass-ta-key technique can let an attacker register an attacker-controlled user-verification key after forcing Chrome to re-register the device.
  • The Golden Pass-ta-key technique can let malware extract the Security Domain Secret used to decrypt synced passkey private keys from Chrome process memory during re-registration or recovery.
  • Unit 42 said eBay fixed a related user-verification validation issue by enforcing Relying Party (RP) User-Verification (UV) checks, demonstrating that server-side implementation validation is also a critical part of the defense. BleepingComputer said Google had not immediately responded to questions about whether the attacks were fully addressed.

Passkeys reduce phishing risk, but the newly disclosed Pass-ta-key attacks show that passwordless authentication can still be undermined when malware compromises a trusted endpoint.

How Malware Exploits Synced Passkeys

The Pass-ta-key attacks target the implementation and trust boundaries around Google Password Manager synced passkeys rather than the cryptographic design of passkeys themselves.

In the basic Pass-ta-key technique, malware running with standard (unprivileged) user rights abuses Chrome’s TPM-backed device identity key to request a valid passkey authentication assertion from Google’s cloud authenticator. According to Unit 42, this attack does not require user interaction, biometric verification, or a PIN once the endpoint has already been compromised.

Silver Pass-ta-key manipulates Chrome’s device re-registration process so an attacker-controlled user-verification key is accepted. Golden Pass-ta-key targets the Security Domain Secret that protects synced passkey private keys. During device recovery or re-registration, malware can extract the 32-byte Security Domain Secret (SDS) while it temporarily resides in unencrypted Chrome process memory during re-enrollment, potentially allowing attackers to decrypt synced passkeys outside the victim device.

The Hexnode Solution

Hexnode XDR can help detect the malware behaviors associated with Pass-ta-key attacks, including suspicious browser process activity, anomalous process trees, credential-access attempts, and indicators of Chrome process memory access or post-authentication compromise. It also enables security teams to investigate and respond to attempts to abuse trusted authentication workflows.

Hexnode UEM can help reduce the attack surface that Pass-ta-key relies on by enforcing browser update compliance, endpoint hardening policies, application controls, and managed-device compliance across enterprise fleets. These controls help limit opportunities for malware to compromise trusted endpoints and abuse browser-based authentication mechanisms.

Hexnode Access, together with IdP-driven Conditional Access integrations such as Microsoft Entra ID and Okta, can help limit the impact of compromised passkeys by restricting access to sensitive business applications to compliant and trusted devices, helping prevent unmanaged or compromised endpoints from accessing enterprise resources even when valid credentials or passkeys are present.

What makes Hexnode the go-to UEM vendor in the market?
Feature Resource

What makes Hexnode the go-to UEM vendor in the market?

Download this White paper to learn the reason you should choose Hexnode when there are other vendors in the market claiming to be better than Hexnode.

Get the Whitepaper

Conclusion

Passkeys remain a major advancement in phishing-resistant authentication, but they do not eliminate the endpoint from the trust chain. To reduce the impact of endpoint compromise, organizations should combine passwordless authentication with:

  • XDR to detect malware, credential-access attempts, and suspicious post-authentication activity.
  • UEM to enforce browser updates, endpoint hardening, and device compliance.
  • Managed enterprise browser policies to enforce secure password manager configurations and restrict unauthorized extensions.
  • Identity-aware conditional access to restrict access to sensitive applications from only compliant and trusted devices.
Share

Alanna River

I’m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.