Attacks Expose Weaknesses in Cloud-Synchronized Passkeys on Windows
Researchers at Palo Alto Networks' Unit 42 have identified three attacks against Google Password Manager's synced passkeys on Windows. The attacks, dubbed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, target different assumptions about how synced passkeys are protected.
The researchers found that malware running with user privileges can use wrapped key material stored in the local passkey state to generate a valid authentication request. This allows attackers to produce WebAuthn authentication assertions without the user verification (UV) flag.
eBay initially accepted these assertions despite requesting user verification, but subsequently changed its implementation to validate the flag correctly after being informed of the issue. Unit 42's findings do not show that an attacker can break public key cryptography passkeys.