🔒Pass-ta-key Attack Exposes Passkeys in Google Password Manager
Your passkeys aren't as secure as you think on Windows
TL;DR
A new attack, Pass-ta-key, exploits vulnerabilities in the Google Password Manager app for Windows. Malware can steal all stored passkeys when running on an infected machine. This affects users relying on TPM storage.
Pass-ta-key exposes a critical vulnerability in how passkeys are managed within the Google Password Manager app on Windows devices. The attack leverages malware to extract passkeys, undermining their security benefits over traditional passwords. Developers and IT teams need to be cautious about storing sensitive data locally, especially on platforms like Windows where apps often run with full user privileges. Pass-ta-key can obtain all stored passkeys when the GPM app is running on an infected machine, highlighting a significant risk for users who rely on TPM storage without additional security measures.

Key Points
Malware can extract all passkeys stored in the Google Password Manager app on Windows, compromising security.
Windows apps typically run with full user privileges, making them more susceptible to such attacks compared to other platforms.
Pass-ta-key uses malware access to Google accounts and TPM-stored keys to retrieve secret passkeys from infected machines.
The most powerful attack variant allows the infected machine to masquerade as an iPhone, transferring keys seamlessly.
Server-stored passkeys are now preferred by many third-party apps for Windows, including 1Password and Dashlane.
Why It Matters
If you're using Google Password Manager on a Windows device with local storage enabled, your passkeys are at risk. Malware can steal all stored passkeys, compromising security. Smaller teams should consider cloud-stored options or stricter app permissions to mitigate this threat.
Frequently Asked Questions
Why does this matter?
If you're using Google Password Manager on a Windows device with local storage enabled, your passkeys are at risk. Malware can steal all stored passkeys, compromising security. Smaller teams should consider cloud-stored options or stricter app permissions to mitigate this threat.
What happened?
A new attack, Pass-ta-key, exploits vulnerabilities in the Google Password Manager app for Windows. Malware can steal all stored passkeys when running on an infected machine. This affects users relying on TPM storage.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 2,944 builders reading daily.