PALO Alto Networks has revealed new attack methods targeting passwordless authentication, specifically targeting Google-synced passkeys. Named 'Pass-ta-key', these attacks allow malware on a Windows machine to hijack passkey-protected accounts without user interaction. The malware can retrieve a device identity key via the Chrome browser and generate authentication signatures without elevated permissions.
Variants of the attack include 'Silver Pass-ta-key', which registers a malicious key during the authentication process, and 'Golden Pass-ta-key', that extracts a master secret to decrypt all associated passkeys. Google has been informed and has implemented mitigations.