Pass-ta-key Attacks Exposed: Malware Can Bypass Biometrics to Steal Passkeys

TechNadu · x · 2026-08-04

Security researchers disclosed three attack methods dubbed 'Pass-ta-key,' emphasizing that while passkeys themselves weren't broken, the implementation around them was flawed.

Studies show that if malware is already running with the logged-in user's privileges, attackers can authenticate to Google-synced passkeys without triggering the device's biometrics or unlock prompts. The research also highlighted risks like extracting the Security Domain Secret (SDS), and relevant vendors have patched the issues following disclosure.

Original post →

More from Safety

Safety channel →