New "Pass-ta-key" Attack Steals Google Passkeys Without Passwords or Biometrics
RedSide Security August 04, 2026 Vulnerability 72 views
Researchers have disclosed three new attacks—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—that allow malware on compromised Windows systems to hijack Google-synced passkeys without passwords or biometrics. The findings expose weaknesses in Chrome's Cloud Authenticator implementation rather than the underlying passkey cryptography.