Technologist Mag
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
OpenAI Is Developing a ‘Persistent’ AI Agent

OpenAI Is Developing a ‘Persistent’ AI Agent

27 August 2026
Sony just launched this model. It’s affordable for OLEDs and has four HDMI ports

Sony just launched this model. It’s affordable for OLEDs and has four HDMI ports

27 August 2026
This Is How Anthropic Thinks AI Agents Should Navigate the Physical World

This Is How Anthropic Thinks AI Agents Should Navigate the Physical World

27 August 2026
Google cracks down on memory-hogging Android apps amid an AI-fueled RAM shortage

Google cracks down on memory-hogging Android apps amid an AI-fueled RAM shortage

27 August 2026
The Wolf Among Us Remastered Emerges From The Shadows On October 29

The Wolf Among Us Remastered Emerges From The Shadows On October 29

27 August 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Technologist Mag
SUBSCRIBE
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release
Technologist Mag
Home » Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
Tech News

Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google

By technologistmag.com5 August 20263 Mins Read
Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
Share
Facebook Twitter Reddit Telegram Pinterest Email

Passkeys have been pushed as the safer successor to passwords. It promised protection from phishing, credential reuse, and password leaks. Google even claims that it cannot be copied or accidentally handed to someone else. But it might not be as secure as the company wants it to be.

Security researchers (Via BleepingComputer) have now found three ways malware can undermine those promises for passkeys synced through Google Password Manager. The techniques, collectively named Pass-ta-key, target Google Password Manager inside Chrome on Windows computers equipped with a Trusted Platform Module. Every attack requires malware to already be running on the victim’s computer.

The researchers did not break the cryptography behind passkeys. They exploited weaknesses in device trust, account recovery, onboarding, and how services verify that the user actually unlocked their device.

Malware can impersonate your trusted computer

The first Pass-ta-key technique lets malware use Chrome’s TPM-backed device identity to request a valid passkey response from Google’s cloud authenticator. It requires no administrator privileges, biometric scan, PIN, device unlock, or interaction from the victim. Google’s service sees the request as coming from a trusted computer and returns the authentication response needed to sign in.

Websites are supposed to check a flag confirming that the user verified their identity. Unit 42 found that GitHub correctly rejected the attack, while eBay accepted it despite supposedly requiring verification. eBay fixed that gap after the researchers reported it.

The more advanced Silver Pass-ta-key attack can force Chrome to register a verification key controlled by the attacker. That key is then treated as proof that the victim entered a PIN or used biometrics, allowing account access from another computer after the original device goes offline.

Google account prompt explaining passkeys.

The worst attack steals the keys themselves

The Golden Pass-ta-key technique targets the master secret used to encrypt every passkey synced through a Google account. Researchers initially found that Chrome exposed this secret in plain text through its internal FIDO logs. Google removed it from the logs following disclosure. However, Unit 42 says the key still temporarily appears inside Chrome’s process memory during device registration or recovery. Malware can extract it and decrypt the victim’s synced passkeys.

The stolen master key could reportedly expose existing and future passkeys. Unit 42 adds that Google’s current implementation provides no method to rotate or revoke that secret after it has been compromised. Passkeys remain substantially safer against phishing and password leaks. Google’s documentation still accurately describes those advantages. This research shows that malware already inside your computer can attack the infrastructure surrounding the passkey instead.

Share. Facebook Twitter Pinterest LinkedIn Telegram Reddit Email
Previous ArticleMotherboards may be the next PC component to get a massive price increase
Next Article Google Drive steps up its video collaboration game with timestamped comments

Related Articles

OpenAI Is Developing a ‘Persistent’ AI Agent

OpenAI Is Developing a ‘Persistent’ AI Agent

27 August 2026
Sony just launched this model. It’s affordable for OLEDs and has four HDMI ports

Sony just launched this model. It’s affordable for OLEDs and has four HDMI ports

27 August 2026
This Is How Anthropic Thinks AI Agents Should Navigate the Physical World

This Is How Anthropic Thinks AI Agents Should Navigate the Physical World

27 August 2026
Google cracks down on memory-hogging Android apps amid an AI-fueled RAM shortage

Google cracks down on memory-hogging Android apps amid an AI-fueled RAM shortage

27 August 2026
AI Agents Are Hacking Systems. Could That Push the US and China to Cooperate?

AI Agents Are Hacking Systems. Could That Push the US and China to Cooperate?

27 August 2026
Gemini Notebook now lets you reference books and turn them into different formats

Gemini Notebook now lets you reference books and turn them into different formats

27 August 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Don't Miss
Sony just launched this model. It’s affordable for OLEDs and has four HDMI ports

Sony just launched this model. It’s affordable for OLEDs and has four HDMI ports

By technologistmag.com27 August 2026

OLED TVs have become considerably more accessible over the years, but buying one from a…

This Is How Anthropic Thinks AI Agents Should Navigate the Physical World

This Is How Anthropic Thinks AI Agents Should Navigate the Physical World

27 August 2026
Google cracks down on memory-hogging Android apps amid an AI-fueled RAM shortage

Google cracks down on memory-hogging Android apps amid an AI-fueled RAM shortage

27 August 2026
The Wolf Among Us Remastered Emerges From The Shadows On October 29

The Wolf Among Us Remastered Emerges From The Shadows On October 29

27 August 2026
AI Agents Are Hacking Systems. Could That Push the US and China to Cooperate?

AI Agents Are Hacking Systems. Could That Push the US and China to Cooperate?

27 August 2026
Technologist Mag
Facebook X (Twitter) Instagram Pinterest
  • Privacy
  • Terms
  • Advertise
  • Contact
© 2026 Technologist Mag. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.