Pass-ta-key Attacks Exposed: Malware Can Bypass Biometrics to Steal Passkeys
TechNadu · x · 2026-08-04
Security researchers disclosed three attack methods dubbed 'Pass-ta-key,' emphasizing that while passkeys themselves weren't broken, the implementation around them was flawed.
Studies show that if malware is already running with the logged-in user's privileges, attackers can authenticate to Google-synced passkeys without triggering the device's biometrics or unlock prompts. The research also highlighted risks like extracting the Security Domain Secret (SDS), and relevant vendors have patched the issues following disclosure.
More from Safety
- Securing AI Agents: An MCP Payment Flow That Cannot Hijack Private Keys — pvdyck · 2026-08-04
- NVIDIA and 120+ Orgs Propose SAFE Guidelines for AI Cybersecurity — nvidia · 2026-08-04
- Cyera Launches Agent Guardian to Monitor On-Device AI Agents — shashib · 2026-08-04
- Tinder Halts AI Feature That Altered Users' Smiles and Complexions — Polymarket · 2026-08-04
- OpenAI Faces Over 50 Lawsuits Since 2023, Leading AI Industry — tegmark · 2026-08-04
- EU AI Act Takes Effect, DeepSeek Tops Global API Usage — 快鲤鱼 · 2026-08-04