Pass-ta-key: Three Attack Techniques Extract Google’s Synced Passkeys From Chrome Memory — 32-Byte Master Key, No Admin Rights Required, No CVE, Two Issues Unresolved
Palo Alto Networks Unit 42 disclosed three attack techniques — Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — against Google Password Manager’s cloud authenticator in Chrome on Windows. All work at ordinary user privilege, with no admin rights. None break WebAuthn cryptography. Golden Pass-ta-key extracts the 32-byte Security Domain Secret from Chrome process memory during re-enrollment — the master key that decrypts every synced passkey private key. No rotation or revocation path exists. Google fixed the log exposure; two of three underlying Chromium issues remain open. No CVE assigned. Passkeys still defeat phishing — these attacks require endpoint malware first.
