Palo Alto Networks Pass-ta-key analysis of passkey-hijack attack methods
Technical Analysis
Summary
Hide ▲
Show ▼
Palo Alto Networks disclosed Pass-ta-key, a new set of attack methods that lets malware on Windows machines running Chrome hijack Google-synced passkeys and take over accounts. The technique bypasses the normal trust flow by abusing Chrome sync data and device identity material to produce a valid authentication assertion. A re-registration variant, Silver Pass-ta-key, can enroll attacker-controlled verification keys for later use, while Golden Pass-ta-key can expose secrets that decrypt synchronized passkey private keys. The findings raise the practical risk of passwordless account compromise even when no phishing prompt or elevated privileges are involved.
Related Happenings
Pass-ta-key attacks against Google Password Manager on Windows TPM devices
Technical Analysis
H score23
First: 04.08.2026 02:58
Last: 04.08.2026 02:58
Sources 1
About this happening:
Pass-ta-key identifies three attacks that let malware on already-compromised Windows devices abuse Google Password Manager synced passkeys. The techniques can impers...
Pass-ta-key attacks against Google Password Manager on Windows TPM devices
Technical AnalysisAbout this happening: Pass-ta-key identifies three attacks that let malware on already-compromised Windows devices abuse Google Password Manager synced passkeys. The techniques can impers...
Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical Analysis
H score3
First: 03.08.2026 19:24
Last: 03.08.2026 19:24
Sources 1
About this happening:
Researchers documented three post-compromise techniques against Chrome's Google Password Manager on Windows, showing how malware on a compromised endpoint can steal or min...
Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical AnalysisAbout this happening: Researchers documented three post-compromise techniques against Chrome's Google Password Manager on Windows, showing how malware on a compromised endpoint can steal or min...
PAN-OS GlobalProtect CVE-2026-0257 exploitation wave
Exploitation Wave
H score18
First: 01.06.2026 11:30
Last: 01.06.2026 11:30
Sources 1
About this happening:
CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....
PAN-OS GlobalProtect CVE-2026-0257 exploitation wave
Exploitation WaveAbout this happening: CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....
Venom Stealer MaaS infostealer with persistent credential harvesting
Malware Activity
H score29
First: 31.03.2026 17:51
Last: 31.03.2026 17:51
Sources 1
About this happening:
The Venom Stealer infostealer now ships as malware-as-a-service (MaaS), expanding access to a persistent credential-theft tool and raising risk for Windows users. It s...
Venom Stealer MaaS infostealer with persistent credential harvesting
Malware ActivityAbout this happening: The Venom Stealer infostealer now ships as malware-as-a-service (MaaS), expanding access to a persistent credential-theft tool and raising risk for Windows users. It s...
Jinkusu's Starkiller phishing-as-a-service ecosystem commoditizes account takeover
Threat Actor Meta
H score37
First: 20.02.2026 22:00
Last: 20.02.2026 22:00
Sources 1
About this happening:
A new phishing-as-a-service operation tied to Jinkusu is proxying real login pages through attacker infrastructure, making MFA bypass and account takeover easier for low-s...
Jinkusu's Starkiller phishing-as-a-service ecosystem commoditizes account takeover
Threat Actor MetaAbout this happening: A new phishing-as-a-service operation tied to Jinkusu is proxying real login pages through attacker infrastructure, making MFA bypass and account takeover easier for low-s...
Timeline
-
05.08.2026 15:48 2 articles · 2h ago
Palo Alto Networks discloses Pass-ta-key passkey hijack methods
Initial DisclosurePalo Alto Networks disclosed Pass-ta-key, a set of attack methods targeting Google-synced passkeys in Chrome on Windows that can let malware on a compromised machine inspect local sync data, recover device identity material, and generate valid authentication assertions without user interaction or elevated privileges. The disclosure also described Silver Pass-ta-key device re-registration abuse and Golden Pass-ta-key memory extraction, and said Google had been notified while mitigations were rolled out.
Show sources
- New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts — www.securityweek.com — 05.08.2026 15:48
- New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts — www.securityweek.com — 05.08.2026 15:48