- New research "Pass the Passkey" by Palo Alto Networks Unit 42 reveals three critical vulnerabilities in the Google Password Manager Chrome.
- Pass-ta-key attacks require prior infection of the computer with malware, bypassing biometrics and exposing credentials.
- Despite security gaps, passkeys remain overwhelmingly more secure than traditional passwords.
Frequently Asked Questions about Passkeys and Google Password Manager
Are Passkeys finally safe after the Unit 42 investigation?
Yes, as long as your device is not already infected with malware, as the attacks require local access.
How does the Pass-ta-key attack work in Chrome?
The malware exploits weaknesses in the way the browser manages keys and logs in the device's memory.
Do I need to go back to traditional passwords?
Under no circumstances, as passwords are much more vulnerable to phishing and brute-force attacks.
Passkeys were marketed as the definitive end of passwords, but cybersecurity researchers are here to shake things up. In our own testing in test environments, we saw that the theory of absolute security runs into serious obstacles in practice.
The three methods of attack
According to technical analysis by Palo Alto Networks, hackers can attack Google Password Manager in Chrome in three different ways. The first method hijacks the identity key by exposing it to disk instead of keeping it isolated in the hardware TPM.
The second method tricks the browser into thinking that biometric authentication has been performed. The PC remains in a waiting state, allowing the malware to infiltrate and insert its own keys.
The third and most dangerous route targets the Security Domain Secret (SDS). As we saw when using Chrome, this key used to be leaked in plain text in the logs, but is now located in memory where a memory dump is enough for the malware to grab it.
https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js?client=ca-pub-9816651697894810
(adsbygoogle = window.adsbygoogle []).push({});
What does this mean for your device?
None of these gaps matter if your computer is clean of malware. In the TechNoid lab, we noticed that all tests require prior local infection, which means that the most important firewall remains your own caution about what you download.
It doesn't break the encryption itself, but it bypasses Chrome's credential management logic. If you use public Wi-Fi or download cracked programs, no authentication technology can save you from a compromised device.
Our opinion at TechNoid
New research debunks the myth that passkeys are magical and invulnerable in every scenario. But let's not get too crazy; passkeys are still overwhelmingly more secure than putting "123456" or your date of birth everywhere.
Google should immediately close the memory management loopholes in Chrome, but the responsibility remains hybrid. Keep your operating system up to date and don't look for an excuse to go back to vulnerable passwords.


