Key takeaways
Exploits Identified: Researchers from Palo Alto Networks’ Unit 42 discovered three attacks—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—targeting Google’s passkey system, each progressively more dangerous.
Malware Requirement: All attacks require the victim’s device to be infected with malware, which can impersonate users, steal session data, or exfiltrate the master secret protecting synced passkeys.
Master Secret Theft: The most severe exploit allows attackers to steal the master key, giving access to all synced passkeys across devices. Some vulnerabilities, like the eBay issue, have already been patched by Google.
Palo Alto Networks’ Unit 42 detailed three Google passkey exploits
Attacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeys
Google implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directly
Security researchers from Palo Alto Networks’ Unit 42 have found three ways to exploit Google’s passkey system and log into people’s PIN- or biometrics-protected accounts.
They named these ways ‘Pass-ta-key’, ‘Silver Pass-ta-key’, and ‘Golden Pass-ta-key’, each being progressively more dangerous than the previous one.
While it sounds mighty dangerous, there are major caveats to the exploit, and some of the holes have been plugged already.