Passkeys are increasingly adopted as a more secure alternative to traditional passwords, but new research reveals weak points when an attacker already controls a user’s device. Security researchers at Unit 42 demonstrated several techniques—collectively called the “Pass‑ta‑key” attacks—that can defeat Google Chrome’s passkey protections on compromised Windows machines.
Passkeys replace typed passwords with cryptographic credentials bound to a user’s device and often protected by biometric unlocks or hardware-backed storage. That model reduces many risks associated with passwords, such as phishing and credential stuffing. However, Unit 42’s analysis shows that if malware is present on the endpoint, attackers can interfere with the passkey lifecycle at critical moments: creation, storage, and authentication.
The research focuses on how Chrome and Google Password Manager implement a cloud-based authenticator model and where sensitive data or state can leak. Importantly, these attacks require prior device compromise. A clean machine that has not been infected by malware is not subject to these bypasses, but once an attacker gains persistent access, several passkey protections can be undermined.
Unit 42 describes multiple variants of the Pass‑ta‑key technique. The first variant involves malware exporting the identity key material to disk instead of allowing it to remain protected by the Trusted Platform Module (TPM). In this scenario, the malicious software extracts the key material and uses it to authenticate through Google Password Manager without the user’s consent, effectively impersonating the legitimate account holder.
A second variant—referred to as the “silver” method—targets the user verification flow. The malware manipulates the device state so that Chrome’s password manager believes biometric verification or another user verification (UV) step was completed, even though the user did not approve it. While the system reflects a pending or partially completed verification status, the malware registers its own keys or proceeds with authentication, allowing future logins to be accepted.
The most impactful technique, labeled the “golden” method, exploits information leakage from Chrome’s encryption process. The researchers observed that sensitive cryptographic material from the SDS (the encryption scheme used in the flow) can end up in a place where it persists in Chrome’s process memory. Although attempts were made to remove such traces from logs, remnants in memory can be dumped by malware. By extracting these remnants, an attacker can reconstruct or obtain the database of synced passkeys, enabling decryption of existing credentials.

Unit 42 warns that when the SDS or equivalent secret is leaked, it becomes a blueprint for decrypting future passkeys generated by Google Password Manager on that account. Without rotating or regenerating those underlying secrets, newly created passkeys remain exposed to the attacker who controls the SDS information.
The researchers tested their methods against several services. They report that the initial Pass‑ta‑key technique was effective on a site that failed to properly validate whether user verification had occurred. Other specific services were not named in the public summary, but Unit 42 stated that it reached out to affected vendors with details.
While these findings point to real risks, they do not mean passkeys as a concept are fundamentally broken. Passkeys remove many common attack vectors tied to passwords, such as reuse and phishing. The core takeaway is that endpoint security remains critical: if an attacker already controls a device, they can exploit implementation details and memory artifacts to bypass higher-level protections.
Unit 42 disclosed the vulnerabilities to Google and highlighted that other cloud-based passkey providers using similar models may face comparable risks. Mitigations generally center on reducing sensitive data leakage, improving how Chrome and password managers handle in‑memory cryptographic material, and forcing key regeneration or revocation after suspected compromise.
For organizations and individuals, the research reinforces two practical points: maintain strong endpoint protection to prevent malware infection in the first place, and promptly rotate or revoke passkeys if a device compromise is suspected. Combined with ongoing fixes to browser and password manager implementations, these measures will help preserve the security advantages that passkeys offer over traditional passwords.