SummaryResearchers disclosed three attack techniques collectively known as Pass-ta-key, targeting Google Password Manager’s synced passkeys in Chrome on Windows systems with TPM support. The techniques require malware to already be running on the endpoint and do not break passkey cryptography. Instead, they exploit device-trust, onboarding, recovery, and validation weaknesses. The attacks may allow malware to request valid passkey assertions, register attacker-controlled user-verification keys, or extract the master secret used to decrypt synchronized passkeys. The most serious scenario could expose existing and future passkeys associated with the account. The research represents a controlled demonstration, not confirmed active exploitation. Organizations should continue adopting passkeys while strengthening endpoint controls, monitoring device enrollment and recovery activity, and ensuring services strictly validate user-verification signals during authentication. Key Takeaways• Pass-ta-key consists of three newly demonstrated attacks against Google-synced passkeys on Chrome for Windows. • Every technique requires malware to be present on the victim’s endpoint first. • The basic attack can generate a valid authentication assertion without administrator privileges, device unlock, biometrics, or user interaction. • Silver Pass-ta-key can register an attacker-controlled verification key and support authentication from a separate system. • Golden Pass-ta-key may expose the master secret used to decrypt existing and future synchronized passkeys. • The attacks exploit implementation and trust-flow weaknesses rather than breaking passkey cryptography. • Organizations should strengthen endpoint detection, monitor passkey recovery activity, and require strict user-verification validation. KeywordsPass-ta-key, Silver Pass-ta-key, Golden Pass-ta-key, Google Password Manager, Google Chrome, passkey security, passwordless authentication, WebAuthn, FIDO2, Trusted Platform Module, TPM security, synced passkeys, account takeover, user verification bypass, security domain secret, credential theft, endpoint malware, identity security, Digital Warfare Podcast, cybersecurity, threat intelligence