Pass-ta-key attacks turn endpoint malware into passkey account takeover

Unit 42 details three ways malware can abuse Chrome's synced passkey flows to hijack accounts.

CSBadmin
2 Min Read

Unit 42 has published details on three attack paths, collectively named Pass-ta-key, that let malware on a compromised endpoint take over passkey-protected accounts. All three abuse Google’s synced passkey ecosystem and the Cloud Authenticator that desktop clients rely on.

Path one pulls Chrome’s wrapped device identity key and has the machine’s own TPM sign an attacker-crafted request using Windows CNG calls. The Cloud Authenticator then issues a valid assertion whose only flaw is an unset User Verified bit. GitHub refused the test assertion; eBay accepted one until it closed the validation gap after being told about it.

Silver Pass-ta-key pushes Chrome into a re-enrollment window where no user-verification key exists yet, letting the attacker register a key of their own; assertions signed with it carry the UV flag, so later logins work without the victim’s device. Golden Pass-ta-key triggers re-enrollment and pulls the security-domain secret from Chrome’s process memory while it is briefly in plaintext, then uses it to recover synchronized passkey private keys.

The reach matters because Google syncs passkeys across platforms and into Google Password Manager, so a single compromised endpoint extends everywhere. Relying parties that enforce user verification can defeat the first path, and Unit 42 urges hardware attestation for newly enrolled devices. As of August 3, neither Google nor eBay had published notices describing fixes for all three paths.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.