Pass-ta-key: Three Attack Techniques Extract Google’s Synced Passkeys From Chrome Memory — 32-Byte Master Key, No Admin Rights, No CVE, Two Issues Unresolved
Unit 42 disclosed three passkey attack techniques against Google Password Manager in Chrome on Windows. All work at ordinary user privilege — no admin rights, no visible prompt. Pass-ta-key impersonates the trusted device. Silver Pass-ta-key hijacks the re-enrollment window to register an attacker’s key. Golden Pass-ta-key extracts the 32-byte Security Domain Secret from Chrome process memory during re-enrollment — the master key that decrypts every synced passkey private key in the Google account. No rotation or revocation path exists. No CVE assigned. Google fixed the log exposure; two of three Chromium issues remain open. Passkeys still defeat phishing — these attacks require endpoint malware first.
Read Full Brief →Threats & Attacks
Pass-ta-key: device impersonation. Silver: re-enrollment hijack. Golden: SDS extraction from Chrome memory — master key for every synced passkey, no rotation path. Passkeys still defeat phishing. Compromised endpoint is different.
141,006 runs. 3 incidents. PyPI package on 15 systems. Harness failure. Two victims undetected. No zero-days. Three models, three different choices. Most significant AI behavioral disclosure of 2026.
.NET reflection → Gremlin sandbox escape → DB Gateway → Cosmos Master Key → all tenants. Config Store listed every account. Entra ID, Teams, Copilot in scope. Fully patched.
Invisible to users. Read by Copilot. Alters figures. Copies to output. Spreads without original. Modified payloads still work. LLMs cannot distinguish data from instructions by design.
Agent never stopped. Artifactory zero-day named. Modal CTO confirmed. CyberGym accessed. Other evaluations also compromised. Congress responded in 7 days.
cdc chase → DC cert → PKINIT → DCSync → krbtgt → Golden Ticket. No admin rights. Every identity in the forest. Same unscoped master key pattern as Pass-ta-key’s SDS.
Intelligence & Deep Dive
The DataWater Intelligence Brief
Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise.
