Google Password Manager Passkey Hijack (Pass-ta-key / Silver Pass-ta-key / Golden Pass-ta-key)
First seen Aug 4, 2026 · Updated Aug 4, 2026
Unit 42 researchers disclosed three attack techniques against Chrome's Google Password Manager cloud authenticator that allow user-level malware on a compromised Windows machine to sign into passkey-protected accounts without any biometric, PIN, or user-visible prompt. The strongest variant, Golden Pass-ta-key, targets the underlying master key, enabling silent, persistent account takeover even after remediation. This undermines the core phishing-resistance promise of passkeys when the endpoint itself is compromised.
Technical Analysis
The attacks exploit how Chrome's Google Password Manager cloud authenticator stores and protects passkey material on Windows, allowing malware running with standard (non-admin) user privileges to extract or abuse synced passkey credentials without triggering local authentication prompts (no fingerprint, PIN, or Windows Hello challenge). Three escalating techniques were identified: Pass-ta-key (baseline credential abuse), Silver Pass-ta-key (broader session/credential access), and Golden Pass-ta-key (compromise of the master key protecting all synced passkeys, enabling persistent forgeable access even across credential rotation). This effectively converts a local malware foothold into a full authentication bypass for any account secured by Google Password Manager passkeys, defeating the phishing- and remote-attack-resistance that passkeys are designed to provide. No CVE has been assigned as of this report. For organizations running AI agents or automation on Windows endpoints, any agent, RPA tool, or browser-automation process with passkey-protected access to cloud consoles, API management portals, or SaaS admin panels could have its credentials silently hijacked by co-resident malware, leading to unauthorized API key issuance, agent hijacking, or lateral compromise of connected agent infrastructure.
Affected Systems
Windows machines running Google Chrome with Google Password Manager (cloud/synced passkey) enabled; accounts relying on Chrome-synced passkeys for authentication
Indicators of Compromise
- No specific IOCs published (technique-based disclosure; no known malware samples, hashes, IPs, or domains identified in source reporting)
Remediation Steps
- 1
Harden endpoint security
Deploy and tune EDR to detect anomalous local access to Chrome profile data, credential stores, and password manager processes, especially unsigned or unusual user-level processes touching browser sync data.
- 2
Limit passkey sync scope
Where possible, avoid relying solely on Google Password Manager cloud sync for high-value accounts; use hardware security keys (FIDO2) or platform authenticators tied to TPM-backed storage instead.
- 3
Monitor for account anomalies
Enable and review sign-in logs/alerts for passkey-based logins from unfamiliar devices or sessions that bypass expected biometric/PIN challenges.
- 4
Patch and update
Track Google/Chrome security advisories for a fix addressing the master key protection weakness and apply updates promptly once released.
- 5
Restrict local malware execution
Apply application allowlisting, least-privilege user accounts, and browser extension controls to reduce the chance of user-level malware achieving initial foothold on endpoints that manage sensitive or agent-connected credentials.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.