Passkeys were supposed to be the thing that finally kills passwords. No more phishing, no more reused logins, no more sticky notes on the monitor. But researchers at Palo Alto Networks’ Unit 42 have just shown that Google’s version of passkeys has some ugly cracks, and the worst one lets an attacker walk away with a single key that unlocks every passkey you have.

But but but…before anyone panics and rips passkeys out of their life, here’s the catch. All three attacks, which the team playfully calls “Pass-ta-key,” only work if malware is already running on your Windows PC. So this isn’t a random website reaching in to grab your logins. Someone has to trick you into running something bad first. 

This is precisely what we’ve seen with other recent browser scares, like the flaw that can turn Chrome and Edge updaters into clipboard spies on macOS.

The first trick up their sleeve is also the simplest one. Malware copies the way Chrome talks to Google’s cloud, quietly asks for a valid login, and gets one back without ever asking you for a fingerprint or PIN. It doesn’t always land, thankfully. When Unit 42 tried it on GitHub, GitHub checked whether the user was actually verified and slammed the door, but eBay didn’t check properly, so the attack worked there until Google’s researchers reported it and eBay fixed it.

From there they get more creative, and a fair bit more dangerous. Rather than trying to fake your fingerprint, the attacker registers their own bogus “you unlocked the device” key with Google, and from that point on they can log in from their own computer whenever they feel like it.

pass-the-passkey-attack-chrome

Where it really starts to hurt is the last one, because every passkey you sync through Google is scrambled using a single master key. Unit 42 found that this key, called the security domain secret, gets sent to Chrome during setup and then lingers in the browser’s memory, and once someone grabs it, they can decrypt all of your passkeys at once.

In their words:

Although Google removed this secret from Chrome’s logging output following our report, the SDS is still sent to the client and remains accessible in Chrome’s process memory.

Worse, the researchers say Google currently has no way to rotate or revoke that key, so even after a cleanup, the same secret keeps protecting everything.

Google has been patching hard lately, including an update with 370 security fixes, using AI to fix over a thousand bugs across two releases, and moving to block the malware trick that hijacks your New Tab page. The full technical breakdown is in Unit 42’s report. Passkeys are still safer than passwords. Just don’t treat them as magic once malware is on the machine.

We stand out from the tech-media crowd because we break news stories; we mainly bring you stuff that you won’t find anywhere in the mainstream tech media. Our stories have been picked up by some of the world’s most popular websites and media outlets—more info is available here.

Dwayne Cubbins
2878 Posts

I cover fast-moving stories across apps, online platforms, and everyday tech — phones, wearables, consoles, and whatever else people are fighting with this week. Bugs, rollouts, scams, policy enforcement, and the occasional internet-culture rabbit hole are all fair game. My goal is simple — make confusing tech news readable. When I'm not working, I'm working out or chilling with my dog. Got a tip? You can find me on X @dcubbins.