Palo Alto Networks Unit 42 has disclosed three proof-of-concept attack techniques that can compromise passkey-protected accounts by abusing Google Password Manager’s synced-passkey implementation in Chrome on Windows.
The research focuses on Windows computers equipped with a Trusted Platform Module and begins with malware already running as the logged-in user. The techniques do not break WebAuthn cryptography. They target the local files, device-trust signals, onboarding procedures and recovery mechanisms surrounding the cryptographic keys.
The first technique, called Pass-ta-key, uses a device identity key accessible to Chrome at ordinary user privilege. Malware can make the Trusted Platform Module sign an attacker’s request, allowing Google’s cloud authenticator to return a valid assertion without a device unlock or user interaction.
That basic attack works when a service treats user verification as preferred or fails to validate WebAuthn’s user-verified flag correctly. Unit 42 demonstrated the validation problem against eBay before the company corrected it. Services that require and properly validate user verification reject the basic assertion.
Silver Pass-ta-key targets a stronger configuration. It forces the device back into onboarding and registers an attacker-controlled user-verification key while the account is in a pending state. The attacker can then request verified assertions from another system without keeping the victim’s computer online.
Golden Pass-ta-key extracts the security-domain secret used to decrypt synced passkeys. Google removed that secret from Chrome’s device logs after Unit 42 reported the exposure. The researchers found that malware could still recover it from Chrome process memory while the browser re-registers with the cloud authenticator.
Google has expanded passkey synchronization across Android and desktop platforms, making secure recovery and device enrollment important parts of the credential model. Hardware-security vendors have also added tools for deploying passkeys with external security keys.
Unit 42 recommends that relying parties require user verification and validate the associated flag, while credential managers should verify the attestation of newly registered device keys. It also calls for tighter controls on local passkey data, recovery flows and sensitive key material in browser memory.
Sources: Palo Alto Networks Unit 42, Google Security Blog
–
By the ID Tech Editorial Team




Follow Us