📣 Send us your press release
Site updates every 15 minutes
Technology

New Pass-ta-key Attack Exposes Passkey Storage Vulnerabilities

A researcher from Palo Alto Networks has detailed a "Pass-ta-key" attack that can extract all stored passkeys from Google Password Manager on Windows machines infected with malware. The attack targets a previously unknown attack surface.

11 August 2026
New Pass-ta-key Attack Exposes Passkey Storage Vulnerabilities

Arie Olshtein, a researcher at cybersecurity firm Palo Alto Networks, has identified a novel attack surface impacting the passkey authentication system. Dubbed "Pass-ta-key," the method can extract all passkeys stored by the Google Password Manager (GPM) application on Windows machines, provided the computer is infected with malware and GPM is running.

This discovery has raised concerns, as many users believed passkeys were exclusively stored within the highly secure Trusted Platform Module (TPM) on Windows devices. The Pass-ta-key attack demonstrates a scenario where sensitive credentials stored via GPM can be compromised.

While the researcher emphasizes that the underlying attack vectors are not entirely new, the specific application to passkey extraction via GPM has generated significant attention. The findings aim to clarify the actual security posture of passkeys when implemented through specific applications like GPM.

The research underscores the importance of understanding the exact storage and protection mechanisms of authentication data across different applications and operating systems. Palo Alto Networks' findings provide crucial insights for users and security professionals evaluating the safety of passkey adoption.

Original source: arstechnica.com