eBay and Google: Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint

eBay and Google: Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint

Google Passkey Security Flaws Expose Accounts to Silent Hijacking

New research from Unit 42 reveals critical vulnerabilities in Google’s Cloud Authenticator, allowing malware on compromised Windows devices to hijack synced passkeys and bypass multi-factor authentication (MFA) without user interaction. The findings, part of a three-part series on passkey security, highlight flaws in device trust, onboarding, and recovery mechanisms that undermine the protections passkeys were designed to provide.

Passkeys, which replace passwords with public-key cryptography, are vulnerable due to Chrome’s handling of the "identity key" a hardware-backed credential meant to verify device possession. Instead of being permanently secured in the Trusted Platform Module (TPM), the key is generated as an exportable blob, enabling malware to extract and use it via Windows cryptography APIs to authenticate as the victim. This "Pass-ta-key" attack allows silent logins without triggering biometric or PIN prompts.

A more severe variant, the "Silver Pass-ta-key" attack, exploits Chrome’s re-onboarding process. By corrupting local passkey state files, attackers force the browser to accept a new, attacker-controlled verification key, granting persistent access even to MFA-protected accounts. The most damaging technique, the "Golden Pass-ta-key" attack, targets the security domain secret (SDS), a 32-byte master key encrypting all synced passkeys. Researchers found this key exposed in Chrome’s logs and memory during recovery, allowing attackers to decrypt past and future passkeys creating undetectable, long-term access since Google lacks a mechanism to rotate the SDS.

The vulnerabilities stem from implementation gaps rather than flaws in passkey cryptography itself, particularly over-reliance on client device trust and inconsistent validation by service providers. Some platforms, including eBay, have patched verification gaps following responsible disclosure. Mitigation strategies include enforcing user verification checks, validating device key attestation, restricting local access to credential stores, and monitoring for unusual onboarding or recovery triggers.

Source: https://cybersecuritynews.com/google-synced-passkey-malware-attack/

eBay TPRM report: https://www.rankiteo.com/company/ebay

Google TPRM report: https://www.rankiteo.com/company/google-cloud-official

"id": "gooeba1785781429",
"linkid": "google-cloud-official, ebay",
"type": "Vulnerability",
"date": "8/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 'Users of Google Cloud '
                                              'Authenticator (Chrome on '
                                              'Windows)',
                        'industry': 'Internet Services',
                        'location': 'Global',
                        'name': 'Google',
                        'size': 'Large',
                        'type': 'Technology Company'}],
 'attack_vector': 'Malware on compromised Windows devices',
 'data_breach': {'data_encryption': 'Weak (exportable identity key, exposed '
                                    'SDS)',
                 'sensitivity_of_data': 'High (authentication credentials)',
                 'type_of_data_compromised': 'Passkeys (public-key '
                                             'credentials)'},
 'description': 'New research from Unit 42 reveals critical vulnerabilities in '
                'Google’s Cloud Authenticator, allowing malware on compromised '
                'Windows devices to hijack synced passkeys and bypass '
                'multi-factor authentication (MFA) without user interaction. '
                'The findings highlight flaws in device trust, onboarding, and '
                'recovery mechanisms that undermine the protections passkeys '
                'were designed to provide. Passkeys, which replace passwords '
                'with public-key cryptography, are vulnerable due to Chrome’s '
                "handling of the 'identity key.' Attackers can exploit this to "
                "authenticate as the victim silently. Variants include 'Silver "
                "Pass-ta-key' (persistent access via re-onboarding) and "
                "'Golden Pass-ta-key' (decryption of all synced passkeys via "
                'exposed security domain secret).',
 'impact': {'brand_reputation_impact': 'Undermines trust in passkey security',
            'data_compromised': 'Synced passkeys (public-key credentials)',
            'identity_theft_risk': 'High (silent account hijacking)',
            'operational_impact': 'Bypass of multi-factor authentication (MFA)',
            'systems_affected': 'Google Cloud Authenticator (Chrome on '
                                'Windows)'},
 'investigation_status': 'Research disclosed (patches partially implemented by '
                         'eBay)',
 'lessons_learned': 'Over-reliance on client device trust and inconsistent '
                    'validation by service providers can undermine passkey '
                    'security. Implementation gaps (e.g., exportable keys, '
                    'exposed SDS) create critical vulnerabilities.',
 'post_incident_analysis': {'corrective_actions': ['Permanently secure '
                                                   'identity keys in TPM',
                                                   'Implement stricter '
                                                   'validation for '
                                                   're-onboarding',
                                                   'Encrypt SDS and limit '
                                                   'exposure in logs/memory',
                                                   'Add SDS rotation '
                                                   'mechanism'],
                            'root_causes': ['Exportable identity key (not '
                                            'permanently secured in TPM)',
                                            'Corruptible local passkey state '
                                            'files (re-onboarding exploit)',
                                            'Exposed security domain secret '
                                            '(SDS) in Chrome logs/memory',
                                            'Lack of SDS rotation mechanism']},
 'recommendations': ['Enforce user verification for passkey authentication',
                     'Validate device key attestation to prevent spoofing',
                     'Restrict local access to credential stores',
                     'Monitor for unusual onboarding/recovery triggers',
                     'Rotate security domain secrets (SDS) periodically',
                     'Patch verification gaps in service provider '
                     'implementations'],
 'references': [{'source': 'Unit 42 (Palo Alto Networks)'}],
 'response': {'remediation_measures': ['Enforce user verification checks',
                                       'Validate device key attestation',
                                       'Restrict local access to credential '
                                       'stores',
                                       'Monitor unusual onboarding/recovery '
                                       'triggers'],
              'third_party_assistance': 'Unit 42 (Palo Alto Networks) '
                                        'research'},
 'title': 'Google Passkey Security Flaws Expose Accounts to Silent Hijacking',
 'type': 'Vulnerability Exploitation',
 'vulnerability_exploited': ['Exportable identity key in Chrome’s Cloud '
                             'Authenticator',
                             'Corruptible local passkey state files '
                             '(re-onboarding exploit)',
                             'Exposed security domain secret (SDS) in Chrome '
                             'logs/memory']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.