Threat Intelligence

Malware Could Bypass Passkey Security in Google Password Manager, Researchers Warn

The Hacker News · 4 Aug 2026
Key Takeaway Passkeys are strong protection, but they're only as safe as the device they're stored on—so keep endpoint security and malware protection up to date on any machine used to access business accounts.

Passkeys are widely promoted as a more secure alternative to passwords because they typically require a fingerprint, face scan, or PIN to unlock. However, new research from Unit 42 has revealed three attack methods—dubbed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—that could allow malware running on a Windows computer to bypass these protections entirely when using Chrome's Google Password Manager as a cloud authenticator.

The most severe of these attacks, Golden Pass-ta-key, targets the underlying master key that protects stored passkeys. If malware gains ordinary user-level access to a machine, it may be able to sign into a victim's accounts silently, with no visible prompt, fingerprint scan, or PIN entry required on the victim's screen. This undermines a key selling point of passkeys: that they can't be phished or stolen the way traditional passwords can.

For small businesses relying on passkeys as their main defence against account takeover, this research is a reminder that no security method is foolproof, especially if the underlying device is already compromised by malware. Endpoint security, keeping systems patched, and monitoring for unusual account activity remain essential even when using modern authentication methods like passkeys.

passkeys malware Google Password Manager authentication Windows security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.