Google passkeys were supposed to replace passwords. According to researchers, ordinary malware can steal them from Windows Home News The Palo Alto Networks Unit 42 security team described three new attacks on Google passkeys Malware on Windows can bypass fingerprint and PIN verification and log you in without a single click No one has broken the encryption, but all attacks assume that malicious code is already running on the computer Sdílejte: Adam Kurfürst Published: 10. 8. 2026 12:30 Advertisement Passkeys were supposed to send passwords into retirement – they cannot be disclosed, guessed, or lured out by phishing. However, researchers from Palo Alto Networks have now shown that even passkeys have their limits against a computer already running malware. On Windows, malicious code can exploit Google passkeys entirely on its own, without asking you anything. Passwordless login is slowly becoming the new standard – Google, Apple, and banks are pushing users towards passkeys precisely because they eliminate an entire class of attacks. This was a reaction to years of struggling with leaky and easily guessable passwords. However, new research reminds us that no protection is absolute: if malware gets onto a computer, it can bypass passkeys stored in Google Password Manager just as easily as stored passwords. Experts described three types of attacks According to the published report, the research specifically targets Google passkeys synchronized via the password manager in the Chrome browser, on computers with Windows and a TPM security chip. The crucial condition is clear: a malicious program must already be running on the machine. This program then needs neither administrator rights nor a single user click for its tricks. The authors gave the trio of attacks the collective name Pass-ta-key. The first and simplest variant involves malware mimicking Chrome’s behavior and impersonating the victim’s trusted device. It sends a signature from the security chip to Google’s authentication service, which then returns a valid login, as if the owner were actually sitting at the computer. A defense exists – the target service can ask if the user actually went through authentication. GitHub repelled the attack this way, but eBay did not monitor this single control bit, and the login went through even without a fingerprint or PIN. The error has since been corrected. The second variant goes further. Malware forces Chrome to re-register with Google, and on that occasion, it injects its own authentication key, which the attacker generated themselves. Google accepts it because it doesn’t verify if the key comes from genuine hardware – and from that moment on, it treats every attacker’s signature as proof that the owner unlocked the device with a fingerprint. According to researchers, this can bypass even accounts with strict authentication, including banking accounts. Moreover, it only takes one attack: the attacker can then log in from their own computer, without the victim even needing to be online. The third attack is the worst. It allows the theft of the master key that Google uses to encrypt all synchronized passkeys. Whoever obtains it can decrypt all of the victim’s keys at once – even those that will be created in the future. Researchers found it lying in readable form directly in Chrome’s internal logs. Google fixed the logging, but according to the team, the key is still sent to the browser and can be extracted from its memory. The unpleasant part is that this master key cannot currently be invalidated or replaced – once leaked, it remains valid forever. The risk is not too high But before you start deleting all your passkeys, one crucial caveat: all three attacks assume that malware first gets onto the computer. Furthermore, the research only concerns the combination of Windows, Chrome, and Google Password Manager, not, for example, hardware keys like YubiKey. The authors themselves emphasize that passkeys remain significantly more secure than traditional passwords, and attacking them is still more difficult. The catch is how easily malware can get onto a computer today. Even an automated phishing campaign targeting the general public can distribute malicious code, so a “compromised computer” is far from being just a problem for the careless. And once the code settles in, the described tricks run unnoticed in the background. Palo Alto Networks reported everything to Google and the affected services before publication. Google removed the key leak from logs, eBay fixed the authentication check, and researchers are calling for websites to consistently verify that the user has indeed logged in. For the average person, this leads to an old, but even more valid piece of advice: the best protection for passkeys is not to let malware onto your computer – meaning not to install software from unknown sources and not to fall for phishing. Do you already use passkeys for logging in, or do you still rely on passwords? Sources: Unit 42, BleepingComputer, Cybernews About the author Adam Kurfürst Adam studuje na gymnáziu a technologické žurnalistice se věnuje od svých 14 let. Pakliže pomineme jeho vášeň pro chytré telefony, tablety a příslušenství, rád se… More about the author Sdílejte: Google Google Chrome Hesla kybernetická bezpečnost Malware Zabezpečení