Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical Analysis
Summary
Hide ▲
Show ▼
Researchers documented three post-compromise techniques against Chrome's Google Password Manager on Windows, showing how malware on a compromised endpoint can steal or mint passkey authentication material. The methods, Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, abuse Chrome's device-key handling, re-enrollment flow, and synced-secret handling rather than breaking cryptography. The strongest path targets the 32-byte Security Domain Secret (SDS) that protects synced passkeys, creating reusable access risk after an initial compromise.
Related Happenings
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
Google Chrome DBSC rolls out session-cookie theft protection for all users
Security Tool/Service
H score10
First: 29.05.2026 15:08
Last: 29.05.2026 15:08
Sources 1
About this happening:
Google's Chrome Device Bound Session Credentials (DBSC) is now generally available and rolling out to all users, reducing the risk of account takeovers from stolen...
Google Chrome DBSC rolls out session-cookie theft protection for all users
Security Tool/ServiceAbout this happening: Google's Chrome Device Bound Session Credentials (DBSC) is now generally available and rolling out to all users, reducing the risk of account takeovers from stolen...
Gremlin stealer modular toolkit evolution
Malware Activity
H score21
First: 15.05.2026 17:19
Last: 15.05.2026 17:19
Sources 1
About this happening:
The Gremlin stealer malware has expanded into a modular toolkit with session-hijacking and crypto clipping capabilities, raising the risk of credential theft and a...
Gremlin stealer modular toolkit evolution
Malware ActivityAbout this happening: The Gremlin stealer malware has expanded into a modular toolkit with session-hijacking and crypto clipping capabilities, raising the risk of credential theft and a...
Google Chrome 146 adds Device Bound Session Credentials to block session-cookie theft
Security Tool/Service
H score11
First: 09.04.2026 21:33
Last: 09.04.2026 21:33
Sources 1
About this happening:
Google has rolled out Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, binding sessions to device hardware to blunt infostealer malware that steals s...
Google Chrome 146 adds Device Bound Session Credentials to block session-cookie theft
Security Tool/ServiceAbout this happening: Google has rolled out Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, binding sessions to device hardware to blunt infostealer malware that steals s...
Storm infostealer server-side decryption activity
Malware Activity
H score18
First: 02.04.2026 17:15
Last: 02.04.2026 17:15
Sources 1
About this happening:
The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
Storm infostealer server-side decryption activity
Malware ActivityAbout this happening: The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
Timeline
-
03.08.2026 19:24 2 articles · 1h ago
Unit 42 details three Chrome Google Password Manager passkey attack paths
Initial DisclosurePalo Alto Networks Unit 42 detailed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key against Chrome's Google Password Manager on Windows systems with a Trusted Platform Module (TPM), showing how malware already running on the victim's device can obtain a valid assertion, register an attacker-controlled user-verification key, or extract the 32-byte Security Domain Secret (SDS) used to decrypt synced passkey private keys. The techniques are described as post-compromise paths that do not break the underlying cryptography and can enable reusable access after an initial endpoint compromise.
Show sources
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts — thehackernews.com — 03.08.2026 19:24
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts — thehackernews.com — 03.08.2026 19:24