Risks and Attacks Targeting Passkey Authentication
🔒 This Unit 42 analysis examines novel attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The research demonstrates how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to authenticate without user interaction, bypass user verification, and extract synced passkey private keys. The article outlines three attack variants—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—showing practical exploit paths on Windows Chrome with TPM-equipped devices and emphasizing mitigation via Palo Alto Networks products.
