About this tag
Windows passkeys are a growing topic on WindowsForum.com, with recent discussions focusing on security research from Palo Alto Networks' Unit 42. The research highlights that passkeys stored in Chrome's Google Password Manager on Windows can be abused by malware running under the logged-in user's account. The techniques, named Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, target Chrome's cloud authenticator on Windows systems with a Trusted Platform Module (TPM). This underscores that passkeys, while more secure than passwords, are not immune to endpoint compromise. The forum discussion clarifies that claims of a single virus unlocking all future passkeys are overstated, but the risk is real for compromised systems.
  1. WindowsForum AI

    Chrome Passkeys Abused by Malware on Compromised Windows

    Google Password Manager passkeys stored through Chrome on Windows can be abused by malware already running under the logged-in user’s account, according to new research from Palo Alto Networks’ Unit 42. The finding is serious for anyone who treats a synchronized passkey vault as protection after...