Pass-ta-Key Attack: Why Passkeys Aren't As Secure As You Think (Windows Vulnerability) (2026)

Passkeys, the new authentication method, have been hailed as a more secure alternative to passwords. However, a recent attack called Pass-ta-key has raised concerns among end users and security professionals. This attack, which targets the Google Password Manager app (GPM) on Windows, highlights a fundamental issue with passkeys: their vulnerability to malware on Windows devices.

The Pass-ta-key attack demonstrates how malware can extract passkeys stored in the Google Password Manager app on Windows, even when they are supposed to be protected by the trusted platform manager (TPM). This is because, contrary to common belief, the FIDO 2 specifications do not mandate that passkeys be stored in TPMs or any other dedicated hardware. Most platforms and third-party software store passkeys locally on the device, and Windows is the lone holdout.

The shift to local storage came after developers realized that passkeys needed to be easily synced across devices. However, this decision has led to a security risk on Windows. Unlike other platforms, Windows apps run with all the privileges of the user, making it easier for malware to access the data of a sandboxed app. This is why third-party developers have opted for a new design, storing passkeys in end-to-end encrypted blobs located in the cloud.

The Pass-ta-key attack takes advantage of this design choice. Malware uses its access to the Google account and the user or device key stored in the TPM to obtain the secret passkeys. The most powerful variant causes the infected Windows machine to masquerade as an iPhone, triggering a synchronization capability in GPM that allows users to transfer all stored passkeys to a new device.

However, the author argues that the Pass-ta-key attack is not novel. The risk of malware accessing passkeys has always been present, and it is not unique to passkeys. The attack surface extends to any data that requires authentication for access. The purpose of passkeys is to eliminate shared secrets that can be phished or obtained through server breaches, not to withstand physical attacks against devices.

In conclusion, the Pass-ta-key attack highlights a fundamental issue with passkeys on Windows devices. While it may not be a novel attack, it serves as a reminder that once a device, especially one running Windows, is compromised while logged into an account, all data stored there is vulnerable. Users should be aware of this risk and take appropriate measures to protect their devices and accounts.

Pass-ta-Key Attack: Why Passkeys Aren't As Secure As You Think (Windows Vulnerability) (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Carlyn Walter

Last Updated:

Views: 6751

Rating: 5 / 5 (70 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Carlyn Walter

Birthday: 1996-01-03

Address: Suite 452 40815 Denyse Extensions, Sengermouth, OR 42374

Phone: +8501809515404

Job: Manufacturing Technician

Hobby: Table tennis, Archery, Vacation, Metal detecting, Yo-yoing, Crocheting, Creative writing

Introduction: My name is Carlyn Walter, I am a lively, glamorous, healthy, clean, powerful, calm, combative person who loves writing and wants to share my knowledge and understanding with you.