Utopia Tech
SecurityAI-assisted1 min read

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Security researchers at Unit 42 have identified critical vulnerabilities in Google Password Manager's passkey implementation that allow malware running with standard user privileges on Windows to authenticate to passkey-protected accounts without requiring biometric verification, PINs, or any user interaction. The researchers detailed three distinct attack vectors—Pass-ta-key, Silver Pass-ta-key,

UT

Utopia Tech

August 3, 2026 · 1 min read

Share

Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content