Find notable cyber news and cases, enriched with sources, timelines, and signals.

Pass-ta-key attacks against Google Password Manager on Windows TPM devices

Technical Analysis
First reported
Last updated
Happening score
H score 23
2 unique sources, 2 articles

Summary

Hide ▲

Pass-ta-key is a technical analysis of three attacks against Google Password Manager synced passkeys in Chrome on Windows devices with TPM. Palo Alto Networks Unit 42 showed that malware already on a compromised endpoint can impersonate a trusted device, bypass user-verification checks, and in the most severe case expose the security domain secret used to protect synced passkeys and recover private keys. The findings also showed a validation issue at eBay, and Google removed the secret from Chrome logs after disclosure.

Related Happenings

Microsoft Windows passkey relay mitigation for CVE-2026-34348

Advisory/Mitigation
H score31 First: 10.08.2026 15:25 Last: 10.08.2026 15:25 Sources 1

How related: "We appreciate the work of SpecterOps for reporting this through a coordinated vulnerability disclosure. We have applied mitigations for the reported issue involving passkey relay assertions and continue investing in security enhancements across authentication methods. We recommend adopting a least-privilege access approach, using phishing-resistant authentication methods, and maintaining endpoint protections by embracing a Zero Trust security model to be better protected,"

About this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...

Palo Alto Networks Pass-ta-key analysis of passkey-hijack attack methods

Technical Analysis
H score26 First: 05.08.2026 15:48 Last: 05.08.2026 15:48 Sources 1

About this happening: Palo Alto Networks disclosed Pass-ta-key, a new set of attack methods that lets malware on Windows machines running Chrome hijack Google-synced passkeys and ta...

Chrome Google Password Manager passkey post-compromise techniques on Windows

Technical Analysis
H score3 First: 03.08.2026 19:24 Last: 03.08.2026 19:24 Sources 1

How related: Unit 42 showed attacks against Google Password Manager in Chrome, including a path that recovers the private keys for a victim's synced passkeys.

About this happening: Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate...

Google Dialogflow CX Code Blocks shared-runtime isolation security flaw

Vulnerability
H score32 First: 07.07.2026 19:37 Last: 07.07.2026 19:37 Sources 1

About this happening: Google Dialogflow CX Code Blocks had a shared-runtime isolation flaw that could let one editable agent affect other Code Block-enabled agents in the same Google Cloud pr...

Google Chrome DBSC rolls out session-cookie theft protection for all users

Security Tool/Service
H score10 First: 29.05.2026 15:08 Last: 29.05.2026 15:08 Sources 1

About this happening: Google's Chrome Device Bound Session Credentials (DBSC) is now generally available and rolling out to all users, reducing the risk of account takeovers from stolen...

Timeline

  1. 04.08.2026 02:58 3 articles · 13d ago

    Unit 42 details Pass-ta-key attacks against Google Password Manager on Windows TPM devices

    Technical Analysis Update

    Palo Alto Networks Unit 42 details three Pass-ta-key techniques against Google Password Manager in Chrome on Windows devices with TPM, showing how malware already on a compromised endpoint can impersonate a trusted device, force Chrome to re-register, register an attacker-controlled user-verification key, and extract the security domain secret from Chrome memory to decrypt synced passkeys and recover private keys. Google removed the secret from Chrome logs, and eBay fixed a user-verification validation issue.

    Show sources