Radio
Now Playing
Quickyla Radio — Click to play
Open →
3 min left
Back to News

Think passkeys protect you from hacking and malware? Think again

While most people may have heard of passkeys, many still don’t fully understand how they work . But according to new research, understanding what passkeys don’t protect you from may be just as import…

Think passkeys protect you from hacking and malware? Think again
Android Authority — 4 August 2026
Text:
6 0 0

Affiliate links on Android Authority may earn us a commission. Learn more.

While most people may have heard of passkeys, many still don’t fully understand how they work . But according to new research, understanding what passkeys don’t protect you from may be just as important as understanding what they do.

Researchers from Palo Alto Networks’ Unit 42 (via Bleeping Computer ) uncovered three ways malware on a compromised Windows PC could abuse Google Password Manager’s synced passkeys by exploiting weaknesses in device trust and recovery, rather than breaking passkey cryptography itself.

Notably, every attack requires malware to be running on the victim’s Windows PC. The research targets Google Password Manager’s synced passkeys in Chrome on Windows devices with a Trusted Platform Module (TPM). It’s not a remote exploit against Google accounts.

The first attack, Pass-ta-key, lets malware authenticate without triggering Windows Hello or biometric verification, but only on services that don’t strictly require user verification. The second, Silver Pass-ta-key, goes further by registering an attacker-controlled verification key, allowing the researchers to bypass that limitation. They demonstrated the technique against eBay before responsibly disclosing it, and eBay has since patched the issue.

The most concerning finding is Golden Pass-ta-key. Researchers showed they could recover the master secret protecting synced passkeys, allowing them to decrypt every passkey tied to an account.

Google has removed one of these oversights by eliminating the secret from Chrome’s debug logs, but Unit 42 says it remains recoverable from memory during device re-registration. The report also notes there’s currently no way to rotate or revoke that master secret if it’s compromised.

The takeaway from this report isn’t that passkeys are broken. Unit 42 says the cryptography held up throughout its research. Instead, the attacks expose gaps between the security guarantees users expect and how device trust, onboarding, and recovery work in practice.

Read Full Story at Android Authority →
Advertisement
React:
Sponsored

More to Read

Cardinals OL Isaiah Adams practices despite his recent arre…
💻 Technology
Cardinals OL Isaiah Adams practices despite his recent arrest
Yahoo Sports · 12 days ago
Apple announces Silo’s season 4 return date
💻 Technology
Apple announces Silo’s season 4 return date
9to5Mac · 9 days ago
Alonso pleased with Aston Martin upgrade as Newey targets '…
💻 Technology
Alonso pleased with Aston Martin upgrade as Newey targets 'respectability'
Sky Sports · 11 days ago
Why Tesla Stock Crashed Today
📈 Markets & Finance
Why Tesla Stock Crashed Today
Nasdaq News · 12 days ago
Live: Lebanon's Aoun to meet Trump as pressure builds to di…
🌍 World News
Live: Lebanon's Aoun to meet Trump as pressure builds to disarm Hezbollah
France 24 · 15 days ago
Indian Shares Seen Tad Higher At Open
📈 Markets & Finance
Indian Shares Seen Tad Higher At Open
Nasdaq News · 15 days ago
Full view