Pass-ta-key: Google’s Synchronized Passkeys at Risk from Malware

Pass-ta-key: i passkey sincronizzati di Google a rischio malware

Google’s synchronized passkeys are at the center of new security research raising serious concerns for enterprise environments. Palo Alto Networks’ Unit 42 team has identified three distinct attack paths — collectively dubbed Pass-ta-key — that put organizations using Google Password Manager on Windows endpoints at significant risk.


What Are Pass-ta-key Attacks

Unit 42’s Discovery

Unit 42 researchers published their findings in 2026, revealing that the attack chain begins on a Windows endpoint already compromised by malware. From there, threat actors exploit three separate flows: onboarding, recovery, and device-trust. Crucially, none of these attacks break passkey encryption directly. Instead, they abuse the surrounding processes that make passkeys work.

The most severe outcome is the extraction of the Security Domain Secret — the key that decrypts all passkeys synchronized with a Google account. In practice, a single compromised endpoint can expose an user’s entire digital identity.

How the Attack Works

What makes Pass-ta-key particularly dangerous is that it requires no elevated privileges. Standard Windows user permissions are sufficient, significantly lowering the barrier to entry for attackers. Once malware executes, the threat actor can authenticate without any user interaction, bypassing the identity verification requirements built into the passkey standard.


The Broader Trend: Attacks Are Moving Upstream

From Cryptography to Workflow

Pass-ta-key does not exist in isolation. It reflects a broader and increasingly concerning shift in attacker strategy. Rather than attempting to break passkey cryptography — a formidable challenge — adversaries are now targeting the systems that support it: browsers, enrollment flows, recovery mechanisms, and cloud synchronization.

Other researchers have documented similar techniques in parallel. SquareX demonstrated an attack leveraging malicious browser extensions to manipulate the WebAuthn flow on the client side. Proofpoint described passkey downgrade scenarios targeting Microsoft Entra ID, in which a phishing proxy forces the browser to fall back to weaker authentication methods such as SMS or OTP.

The Threat of Fraudulent Enrollment

One particularly effective tactic is gaining traction: attackers impersonating IT support staff and convincing employees to register an attacker-controlled passkey. The result is persistent, unauthorized access to corporate resources — a technique documented across multiple sectors in recent months.

The message for CISOs is unambiguous. Adopting passkeys reduces certain risks, but it does not eliminate account takeover exposure. The attack surface has simply shifted.


How to Defend Against Pass-ta-key: Endpoints, Enrollment, and Device Trust

Security Team Priorities

The most effective defense starts with Windows endpoint hardening — the origin point of the Pass-ta-key attack chain. Security teams must reduce malware execution paths, limit local user privileges, and enforce centralized management of browser extensions.

Furthermore, any device with passkey synchronization capabilities should be treated as a high-value identity asset. Protecting credentials alone is no longer sufficient; organizations must protect the devices that host them.

Recovery and Enrollment Governance

Hardening endpoints, however, is only part of the equation. Passkey recovery and enrollment flows represent the weakest link in the chain. Organizations must implement additional verification steps for new device registration, including out-of-band approval and rigorous identity proofing by the help desk.

One strategic recommendation stands out: hardware-bound passkeys, which are not synchronized to the cloud, offer significantly stronger protection. Organizations should prioritize authentication models that minimize cloud synchronization exposure wherever possible.

Detection and Monitoring

In this threat landscape, detection is as critical as prevention. SOC teams must monitor for anomalous authenticator registrations and alert on new devices being added to accounts. Suspicious behavior during onboarding flows must be flagged proactively. Even when passkeys are active, a compromised endpoint can bypass user verification and hijack already-authenticated sessions.


Conclusion

Synchronized passkeys represent a genuine step forward from traditional passwords. But Pass-ta-key research makes clear that the attack surface has not disappeared — it has transformed. Adversaries adapt quickly, abusing enrollment, recovery, synchronization, and device-trust mechanisms. For security leaders and CISOs, the priority today is governing the entire digital identity ecosystem, not just the credentials themselves.


Sources:

Source: Original article


The Pass-ta-key research confirms that digital identity security cannot be managed in silos: the timely sharing of threat intelligence between organizations is decisive in anticipating emerging attack vectors such as those that abuse enrollment and cloud synchronization flows. IsacChain enables organizations to share threat information in a secure and verifiable way, while simultaneously supporting automated NIS2 compliance and tracking every intelligence contribution through blockchain verification. In an environment where CISOs must govern the entire identity ecosystem, access to collective and auditable intelligence represents a concrete operational advantage. Discover how IsacChain can help your organization at www.isacchain.com