Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical Analysis
Summary
Hide ▲
Show ▼
Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate passkey handling without breaking cryptography. The newer reporting says the strongest path can recover the 32-byte Security Domain Secret (SDS) for synced passkeys, while related findings from SpecterOps and Dirk-jan Mollema show other post-compromise ways to reuse signed authentication material or a Windows Hello for Business key. The combined event remains centered on endpoint compromise and the surrounding controls that can still leave attackers with reusable authentication material.
Related Happenings
Google Cloud ships quantum-safe key exchange and publishes post-quantum migration roadmap
Security Tool/Service
H score11
First: 13.08.2026 18:00
Last: 13.08.2026 18:00
Sources 1
About this happening:
Google Cloud has begun rolling out quantum-safe key exchange and a staged post-quantum migration roadmap, expanding cryptographic protections for cloud services ahead...
Google Cloud ships quantum-safe key exchange and publishes post-quantum migration roadmap
Security Tool/ServiceAbout this happening: Google Cloud has begun rolling out quantum-safe key exchange and a staged post-quantum migration roadmap, expanding cryptographic protections for cloud services ahead...
OpenAI Anthropic and Google reasoning APIs cross-session replay security flaw
Vulnerability
H score36
First: 12.08.2026 14:47
Last: 12.08.2026 14:47
Sources 1
About this happening:
A newly disclosed cross-session replay flaw in OpenAI, Anthropic, and Google reasoning APIs exposed hidden reasoning and secrets from session logs, including API keys...
OpenAI Anthropic and Google reasoning APIs cross-session replay security flaw
VulnerabilityAbout this happening: A newly disclosed cross-session replay flaw in OpenAI, Anthropic, and Google reasoning APIs exposed hidden reasoning and secrets from session logs, including API keys...
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/Mitigation
H score31
First: 10.08.2026 15:25
Last: 10.08.2026 15:25
Sources 1
How related:
"We appreciate the work of SpecterOps for reporting this through a coordinated vulnerability disclosure. We have applied mitigations for the reported issue involving passkey relay assertions and continue investing in security enhancements across authentication methods. We recommend adopting a least-privilege access approach, using phishing-resistant authentication methods, and maintaining endpoint protections by embracing a Zero Trust security model to be better protected,"
About this happening:
Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/MitigationHow related: "We appreciate the work of SpecterOps for reporting this through a coordinated vulnerability disclosure. We have applied mitigations for the reported issue involving passkey relay assertions and continue investing in security enhancements across authentication methods. We recommend adopting a least-privilege access approach, using phishing-resistant authentication methods, and maintaining endpoint protections by embracing a Zero Trust security model to be better protected,"
About this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Palo Alto Networks Pass-ta-key analysis of passkey-hijack attack methods
Technical Analysis
H score26
First: 05.08.2026 15:48
Last: 05.08.2026 15:48
Sources 1
About this happening:
Palo Alto Networks disclosed Pass-ta-key, a new set of attack methods that lets malware on Windows machines running Chrome hijack Google-synced passkeys and ta...
Palo Alto Networks Pass-ta-key analysis of passkey-hijack attack methods
Technical AnalysisAbout this happening: Palo Alto Networks disclosed Pass-ta-key, a new set of attack methods that lets malware on Windows machines running Chrome hijack Google-synced passkeys and ta...
Pass-ta-key attacks against Google Password Manager on Windows TPM devices
Technical Analysis
H score23
First: 04.08.2026 02:58
Last: 04.08.2026 02:58
Sources 1
How related:
Unit 42's Pass-ta-key research targets Google Password Manager's synced-passkey system in Chrome on Windows.
About this happening:
Pass-ta-key is a technical analysis of three attacks against Google Password Manager synced passkeys in Chrome on Windows devices with TPM. Palo Alto Networks Un...
Pass-ta-key attacks against Google Password Manager on Windows TPM devices
Technical AnalysisHow related: Unit 42's Pass-ta-key research targets Google Password Manager's synced-passkey system in Chrome on Windows.
About this happening: Pass-ta-key is a technical analysis of three attacks against Google Password Manager synced passkeys in Chrome on Windows devices with TPM. Palo Alto Networks Un...
Timeline
-
03.08.2026 19:24 3 articles · 13d ago
Unit 42 details three Chrome Google Password Manager passkey attack paths
Initial DisclosurePalo Alto Networks Unit 42 detailed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key against Chrome's Google Password Manager on Windows systems with a Trusted Platform Module (TPM), showing how malware already running on the victim's device can obtain a valid assertion, register an attacker-controlled user-verification key, or extract the 32-byte Security Domain Secret (SDS) used to decrypt synced passkey private keys. The techniques are described as post-compromise paths that do not break the underlying cryptography and can enable reusable access after an initial endpoint compromise.
Show sources
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts — thehackernews.com — 03.08.2026 19:24
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts — thehackernews.com — 03.08.2026 19:24
- New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA — thehackernews.com — 10.08.2026 15:25