Google Passkeys Targeted by Malware Attack on Windows PCs
Security researchers have warned that malware targeting Windows systems could abuse Google Password Manager and synced passkeys, showing that even passwordless login depends on secure software.

Passkeys were introduced as a safer alternative to traditional passwords, mainly because they are designed to resist phishing and do not expose a reusable password during sign in. Google also allows passkeys to be saved and synchronised through Google Password Manager across supported devices.
However, security research has highlighted a different risk. If malware gains control of a Windows computer, attackers may be able to abuse the software and account mechanisms surrounding synced passkeys. The concern is less about breaking the underlying passkey cryptography and more about what an attacker can do after compromising the device.
How the attack can work
According to the research described in the supplied report, the attack involves malware running on an infected Windows computer and attempting to abuse Chrome and Google Password Manager. Because passkeys can be synchronised between devices, the feature that makes them convenient can also become part of the attack chain when a device is already compromised.
The reported techniques include different methods for abusing authentication and device enrolment. One approach attempts to make use of an existing valid passkey session without necessarily requiring the user to provide a fresh biometric or PIN prompt.
Another technique, described as Silver Pass Ta Key, reportedly abuses device re enrolment to register an attacker controlled user verification key. This could allow the attacker to authenticate from another machine while appearing to act as the victim.
The most serious scenario described as Golden Pass Ta Key involves malware attempting to obtain sensitive security material used to protect synchronised passkeys. If successful, the attacker could potentially decrypt stored passkeys and use them outside the original device environment.
Passkeys are still designed to resist phishing
The findings do not mean that passkeys have suddenly become equivalent to ordinary passwords. Their underlying design remains significantly different.
Passkeys use public key cryptography, with the private key protected by the userβs device or credential system rather than being sent to a website. Google describes passkeys as phishing resistant and says they can be unlocked with a fingerprint, face scan or device PIN.
Google Password Manager also uses a PIN or Android screen lock as a recovery factor when users access saved passkeys on new devices. Google says synchronised passkeys are end to end encrypted so they cannot be accessed by Google itself.
The latest concern therefore highlights an important distinction. A strong authentication system can still be placed at risk when the computer running the browser or password manager has already been infected.
What users should do now
Keeping Windows, Chrome and other regularly used software updated should be a priority. Security products should also have real time protection enabled, particularly on computers used for banking, work and other sensitive accounts.
Users should be equally careful about unexpected email attachments, suspicious downloads and links from unknown sources. Malware often needs an initial foothold before it can attempt to interfere with authentication systems.
Passkeys remain an important step away from vulnerable passwords, but they are not a replacement for basic device security. A properly protected computer is still one of the most important layers between users and account theft.





