Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
This report details a new attack vector, dubbed ‘Pass-ta-key,’ that allows malware running on a compromised endpoint to bypass traditional security measures and gain unauthorized access to passkey-protected accounts. Researchers at Palo Alto Unit 42 discovered that malware can exploit vulnerabilities in Google’s synced passkey ecosystem, specifically within the Cloud Authenticator, to extract private keys and impersonate legitimate devices. The attacks bypass user interaction, device unlock, and PIN verification, presenting a significant threat to the growing adoption of passkey authentication. The core issue lies in the ability of malware to extract and use the device’s identity key, a process that can be accomplished without elevated privileges, making it a particularly insidious risk.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
