These Chrome Attacks Let Malware Steal Passkeys Without a Single Click

·
Listen to this article~5 min
These Chrome Attacks Let Malware Steal Passkeys Without a Single Click

Malware running as an ordinary user on Windows can silently bypass passkey protection in Chrome's Google Password Manager. Unit 42 found three attack paths, including one targeting the master key itself. Here's what you need to know to stay safe.

You'd think passkeys are the ultimate lock on your digital life. No passwords to leak, no phishing bait, just your fingerprint or PIN standing between a hacker and your accounts. But here's the uncomfortable truth: that lock might have a flaw you never saw coming. Security researchers at Unit 42 just revealed something that should make every Windows user pause. Malware running as an ordinary user on your machine can sign into your passkey-protected accounts without your fingerprint, without your PIN, and without anything appearing on your screen. Not a pop-up, not a prompt, not a single telltale sign. ### The Attack That Skips Your Permission Entirely Here's how it works. When you use a passkey through Chrome's Google Password Manager, the system relies on a cloud authenticator to verify your identity. That authenticator is supposed to check with you first. But Unit 42 found three distinct attack paths that bypass that check entirely. - **Pass-ta-key**: The first and simplest approach, which targets the authentication flow itself. - **Silver Pass-ta-key**: A more refined variant that digs deeper into the browser's session handling. - **Golden Pass-ta-key**: The most dangerous one, because it goes after the master key that protects everything else. Think of it like this: your front door has a deadbolt, a chain, and a security camera. But someone discovers they can just walk through the wall. That's what these attacks do to the passkey system. ### Why This Matters for Regular Users The scariest part isn't the technical sophistication. It's the simplicity of the requirement. The malware doesn't need admin rights. It doesn't need to break encryption. It just needs to run as an ordinary user on a Windows machine. That's a bar most malware can clear without breaking a sweat. Once inside, the attacker can silently sign into your Google account, your banking apps, your email, and anything else protected by passkeys. You won't see it happen. You won't get a notification. You'll only find out when it's too late. ### What This Means for Privacy Professionals If you're in the privacy or security space, this is a wake-up call. The whole pitch of passkeys has been that they're unhackable. They're phishing-resistant. They're the future. And while that's still mostly true, this research shows the future has cracks. The attack targets the synchronization between your device and Google's cloud. It exploits the trust model that assumes the device asking for authentication is actually yours. When malware is already running on that device, that assumption falls apart. ### Practical Steps to Protect Yourself You don't need to ditch passkeys entirely, but you should harden your setup. Here's what I'd recommend: 1. **Keep your system clean**: Run regular antivirus scans and avoid downloading sketchy files. Malware has to get on your machine first. 2. **Use a dedicated browser profile**: Separate your sensitive accounts from your everyday browsing. This limits what malware can touch if it does infect you. 3. **Consider an antidetect browser**: For high-stakes accounts, an antidetect browser adds a layer of separation that makes it harder for malware to piggyback on your sessions. It's not a silver bullet, but it raises the bar. 4. **Monitor your account activity**: Check your Google account's security page regularly for unusual sign-ins. You might spot something before it becomes a disaster. ### The Bigger Picture This isn't just about Google or Chrome. It's about the fundamental tension between convenience and security. Passkeys were designed to eliminate passwords, but they still rely on the device being trustworthy. Once that trust is broken, everything else crumbles. Unit 42's research is a reminder that no single security measure is perfect. The best defense is always layered: strong authentication, clean devices, and a healthy dose of skepticism about what's running on your machine. Stay sharp out there. The threat landscape is changing faster than most people realize, and the attackers are always looking for the next crack in the wall.