Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets
Three Pass-ta-key techniques allowed security researchers to work around biometrics-protected locks.
by https://www.techradar.com/uk/author/sead-fadilpai · TechRadarNews By Sead Fadilpašić Published 4 August 2026
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter
- Palo Alto Networks’ Unit 42 detailed three Google passkey exploits
- Attacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeys
- Google implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directly
Security researchers from Palo Alto Networks’ Unit 42 have found three ways to exploit Google’s passkey system and log into people’s PIN- or biometrics-protected accounts.
They named these ways ‘Pass-ta-key’, ‘Silver Pass-ta-key’, and ‘Golden Pass-ta-key’, each being progressively more dangerous than the previous one.
While it sounds mighty dangerous, there are major caveats to the exploit, and some of the holes have been plugged already.
Latest Videos FromTechRadarWatch full video here:
Trusting the wrong device
The biggest caveat is that the victim’s device needs to be infected with malware beforehand. Malware can do all sorts of things, from stealing session cookies to exfiltrating sensitive data, so if a device is tainted with malware, it’s already in trouble.
Still, Unit 42’s findings were important enough to warrant a fix from Google.
In the first technique, the attackers pretend to be the victim. By using malware, they can “ask” Google to log into a passkey-protected account as if it was the victim themselves. Usually, the service being logged into would require a PIN or a fingerprint to confirm the authenticity of the request, but in this scenario, that wasn’t the case.
The method doesn’t work everywhere, though. Unit 42 could not replicate the attack on GitHub, but they succeeded on eBay. The latter later fixed the problem.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors