Radio
Now Playing
Quickyla Radio — Click to play
Open →
3 min left
Back to News

Think passkeys protect you from hacking and malware? Think again

While most people may have heard of passkeys, many still don’t fully understand how they work . But according to new research, understanding what passkeys don’t protect you from may be just as import…

Think passkeys protect you from hacking and malware? Think again
Android Authority — 4 August 2026
Text:
36 0 0

Affiliate links on Android Authority may earn us a commission. Learn more.

While most people may have heard of passkeys, many still don’t fully understand how they work . But according to new research, understanding what passkeys don’t protect you from may be just as important as understanding what they do.

Researchers from Palo Alto Networks’ Unit 42 (via Bleeping Computer ) uncovered three ways malware on a compromised Windows PC could abuse Google Password Manager’s synced passkeys by exploiting weaknesses in device trust and recovery, rather than breaking passkey cryptography itself.

Notably, every attack requires malware to be running on the victim’s Windows PC. The research targets Google Password Manager’s synced passkeys in Chrome on Windows devices with a Trusted Platform Module (TPM). It’s not a remote exploit against Google accounts.

The first attack, Pass-ta-key, lets malware authenticate without triggering Windows Hello or biometric verification, but only on services that don’t strictly require user verification. The second, Silver Pass-ta-key, goes further by registering an attacker-controlled verification key, allowing the researchers to bypass that limitation. They demonstrated the technique against eBay before responsibly disclosing it, and eBay has since patched the issue.

The most concerning finding is Golden Pass-ta-key. Researchers showed they could recover the master secret protecting synced passkeys, allowing them to decrypt every passkey tied to an account.

Google has removed one of these oversights by eliminating the secret from Chrome’s debug logs, but Unit 42 says it remains recoverable from memory during device re-registration. The report also notes there’s currently no way to rotate or revoke that master secret if it’s compromised.

The takeaway from this report isn’t that passkeys are broken. Unit 42 says the cryptography held up throughout its research. Instead, the attacks expose gaps between the security guarantees users expect and how device trust, onboarding, and recovery work in practice.

Read Full Story at Android Authority →
Advertisement
React:
Sponsored

More to Read

I've been buying foreclosed properties for almost 10 years.…
💻 Technology
I've been buying foreclosed properties for almost 10 years. Here's what you should know b…
Business Insider Mkt · 12 days ago
7 States’ Water Systems Hit by Cyberattacks Likely Tied to …
💻 Technology
7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
Wired · 12 days ago
Reddit is letting AI decide when your post breaks the rules
💻 Technology
Reddit is letting AI decide when your post breaks the rules
Android Authority · 7 days ago
Iran war live: Trilateral Mecca defence pact signed, as Hor…
🌍 World News
Iran war live: Trilateral Mecca defence pact signed, as Hormuz deal looms
Al Jazeera · 5 days ago
Saudi intelligence chief meets Iraqi PM, renews Riyadh visi…
🌍 World News
Saudi intelligence chief meets Iraqi PM, renews Riyadh visit invitation
Al Jazeera · 5 days ago
Anne Sweeney Resigns From Netflix Board After 11 Years
💰 Business
Anne Sweeney Resigns From Netflix Board After 11 Years
Variety · 13 days ago
Full view