Pass-ta-key attacks against Google Password Manager on Windows TPM devices
Technical Analysis
Summary
Hide ▲
Show ▼
Pass-ta-key identifies three attacks that let malware on already-compromised Windows devices abuse Google Password Manager synced passkeys. The techniques can impersonate a trusted device, bypass user verification, and in the most severe case recover the security domain secret used to protect synced credentials. The findings show that passkeys still depend on device integrity and on services correctly validating verification signals. They also shift defensive attention to Chrome device trust, recovery flows, and browser-memory exposure on TPM-backed endpoints.
Related Happenings
Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical Analysis
H score3
First: 03.08.2026 19:24
Last: 03.08.2026 19:24
Sources 1
About this happening:
Researchers documented three post-compromise techniques against Chrome's Google Password Manager on Windows, showing how malware on a compromised endpoint can steal or min...
Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical AnalysisAbout this happening: Researchers documented three post-compromise techniques against Chrome's Google Password Manager on Windows, showing how malware on a compromised endpoint can steal or min...
Google Chrome DBSC rolls out session-cookie theft protection for all users
Security Tool/Service
H score10
First: 29.05.2026 15:08
Last: 29.05.2026 15:08
Sources 1
About this happening:
Google's Chrome Device Bound Session Credentials (DBSC) is now generally available and rolling out to all users, reducing the risk of account takeovers from stolen...
Google Chrome DBSC rolls out session-cookie theft protection for all users
Security Tool/ServiceAbout this happening: Google's Chrome Device Bound Session Credentials (DBSC) is now generally available and rolling out to all users, reducing the risk of account takeovers from stolen...
Google rolls out Android Intrusion Logging in Android Advanced Protection Mode
Security Tool/Service
H score10
First: 14.05.2026 16:30
Last: 14.05.2026 16:30
Sources 1
About this happening:
Google has released Android Intrusion Logging for Android Advanced Protection Mode, giving high-risk Android users encrypted forensic logs to investigate suspected s...
Google rolls out Android Intrusion Logging in Android Advanced Protection Mode
Security Tool/ServiceAbout this happening: Google has released Android Intrusion Logging for Android Advanced Protection Mode, giving high-risk Android users encrypted forensic logs to investigate suspected s...
Android 17 expands platform security and privacy protections
Security Tool/Service
H score15
First: 12.05.2026 20:00
Last: 12.05.2026 20:00
Sources 1
About this happening:
Android 17 will add a broad set of Google-backed security and privacy controls next month, reducing exposure to banking scam calls, device theft, and OTP theft...
Android 17 expands platform security and privacy protections
Security Tool/ServiceAbout this happening: Android 17 will add a broad set of Google-backed security and privacy controls next month, reducing exposure to banking scam calls, device theft, and OTP theft...
PromptSpy backdoor for Android with Gemini API automation
Malware Activity
H score22
First: 11.05.2026 16:02
Last: 11.05.2026 16:02
Sources 1
About this happening:
The PromptSpy backdoor for Android was highlighted for using Gemini APIs to automate device interaction, increasing the risk of unauthorized control on infected phones...
PromptSpy backdoor for Android with Gemini API automation
Malware ActivityAbout this happening: The PromptSpy backdoor for Android was highlighted for using Gemini APIs to automate device interaction, increasing the risk of unauthorized control on infected phones...
Timeline
-
04.08.2026 02:58 2 articles · 2h ago
Unit 42 details Pass-ta-key attacks against Google Password Manager on Windows TPM devices
Technical Analysis UpdatePalo Alto Networks Unit 42 details three Pass-ta-key techniques against Google Password Manager in Chrome on Windows devices with TPM, showing how malware already on a compromised endpoint can impersonate a trusted device, force Chrome to re-register, register an attacker-controlled user-verification key, and extract the security domain secret from Chrome memory to decrypt synced passkeys and recover private keys. Google removed the secret from Chrome logs, and eBay fixed a user-verification validation issue.
Show sources
- New Pass-ta-key attacks let malware hijack Google-synced passkeys — www.bleepingcomputer.com — 04.08.2026 02:58
- New Pass-ta-key attacks let malware hijack Google-synced passkeys — www.bleepingcomputer.com — 04.08.2026 02:58