CYBERSECURITYTRACKER
TRACKING7,735 stories in this site build1,671 vulnerability news stories in this site build
Permanent story citation

New Pass-ta-key attack reveals all the things we didn't know about passkeys

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4209

As cited

Copy frozen at (site build).

identity access

New Pass-ta-key attack reveals all the things we didn't know about passkeys

Researcher Arie Olshtein from Palo Alto Networks disclosed a technique called Pass-ta-key that can extract passkeys from Google Password Manager on infected Windows machines, contradicting common assumptions that passkeys are stored exclusively in the trusted platform module (TPM). The attack demonstrates that not all passkeys are protected by TPM hardware isolation, though the underlying vulnerabilities are neither novel nor unique to the passkey authentication mechanism itself. The disclosure has prompted reassessment of passkey security among practitioners and end users.

Why it matters: Organizations and users relying on passkeys for Windows systems need to verify whether their passkey storage uses TPM protection or is vulnerable to malware-based extraction, and should ensure endpoint protection and monitoring are in place to detect compromised credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

New Pass-ta-key attack reveals all the things we didn't know about passkeys

Researcher Arie Olshtein from Palo Alto Networks disclosed a technique called Pass-ta-key that can extract passkeys from Google Password Manager on infected Windows machines, contradicting common assumptions that passkeys are stored exclusively in the trusted platform module (TPM). The attack demonstrates that not all passkeys are protected by TPM hardware isolation, though the underlying vulnerabilities are neither novel nor unique to the passkey authentication mechanism itself. The disclosure has prompted reassessment of passkey security among practitioners and end users.

Why it matters: Organizations and users relying on passkeys for Windows systems need to verify whether their passkey storage uses TPM protection or is vulnerable to malware-based extraction, and should ensure endpoint protection and monitoring are in place to detect compromised credentials.

VendorsMicrosoftGooglePalo Alto Networks
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary