Google Password Manager passkeys could be at risk with new ‘Pass-ta-key’ attack
Passkeys are becoming more popular as a safer alternative to traditional passwords, but some cracks are starting to show after one group successfully bypassed Google’s Chrome-based passkeys using what they call the “Pass-ta-key” attack method.
Google's password manager is facing potential security risks due to a newly discovered "Pass-ta-key" attack method. This technique, outlined by researchers Unit 42, targets Google's Chrome-based passkeys, which are designed to be safer than traditional passwords by utilizing biometric signatures and endpoint security. The attack employs several methods, all of which rely on malware infecting a Windows machine.
One method involves taking control of a protected account and exporting the identity key to a disk instead of the Trusted Platform Module (TPM). This allows the malware to authenticate with Google Password Manager without the user's consent. The "silver" method goes further by tricking the password manager into believing the device has been unlocked using biometrics, allowing the malware to register its own keys and approve future ones.
The "golden" method is the most dangerous, as it leaks encryption data into Google Chrome's log system. Even after Google removed this information, it remains in Chrome process memory. Malware can collect this data by dumping Chrome's memory and obtaining a database of the user's synced passkeys. The most frightening aspect is that this method allows any future passkeys generated through Google Password Manager to be easily decrypted by the attacker.
Once the stolen Security Dependencies Specification (SDS) is acquired, it serves as a template and bypass for all future passkeys, rendering them vulnerable unless a new SDS is generated.
While the first Pass-ta-key method only affected eBay due to its lack of UV process validation, the other methods bypass user verification entirely. Google has been notified of the discovered exploits, and other passkey providers also utilize the same cloud authenticator model. Although passkeys are generally safer than traditional passwords, the vulnerabilities outlined in Google Chrome's process memory remain susceptible to attack, particularly when malware is present.
Written by urgent.news from 9to5Google's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.