// Google CloudHIGH
Palo Alto Networks Unit 42 disclosed three attack techniques (Pass-ta-key, Silver Pass-ta-key, Golden Pass-ta-key) that enable malware on a compromised Windows device to hijack Google passkey-protected accounts without requiring device unlock, user interaction, or privilege escalation. The attacks exploit weaknesses in Google's cloud authenticator and device re-enrollment workflows, potentially allowing extraction of all synced passkey private keys. Unit 42 recommends enforcing strict user verification policies and strengthening recovery workflows.
- Malware Can Steal Google’s Synced Passkeys Without Password or F(opens in a new tab)
- Pass the Passkey: A Novel Attack Surface in Passwordless Authent(opens in a new tab)
- New Pass-ta-key attacks let malware hijack Google-synced passkey(opens in a new tab)
- Experts reveal Google Password Manager can be hijacked to let ha(opens in a new tab)
// Get alerts for Google Cloud