Filed under: Cybersecurity — Browser Security — August 2026
What happened
Security researchers at Unit 42 disclosed three proof-of-concept attack methods, nicknamed “Pass-ta-key,” that let malware already running on a Windows PC steal passkeys saved in Google Password Manager, Chrome’s built-in passkey vault. The most serious version can pull the master key that protects every passkey synced to a Google account straight out of Chrome’s memory — and unlike a stolen password, that key can’t be changed or revoked once it’s taken. This is research only, not an active attack: all three methods require a device to already be infected with other malware first, and there is no evidence of real-world use yet.
Why it matters to your business
Passkeys have been promoted as the fix for phishing, and more small businesses — including ones we work with — have started turning them on for Microsoft 365, Google Workspace, and banking logins. This research doesn’t undo that; a passkey still can’t be phished away over email or a fake login page. But it’s a reminder that a passkey is only as safe as the computer it lives on, and right now there’s no patch for this specific weakness — just the reality that basic malware protection matters more than ever.
What to do this week
Keep using passkeys — they still block the phishing attacks that steal most passwords. Alongside them, make sure Microsoft Defender (or your endpoint antivirus) is active and up to date on every Windows PC, and that no one has quietly turned off real-time protection. In Chrome, go to Settings > Privacy and security > Security and confirm “Enhanced protection” is turned on. Review who has local administrator rights on company laptops — fewer admin accounts means fewer easy footholds for malware to gain the access this attack depends on. There’s no fix to install yet, so watch for a Chrome or Google Password Manager update addressing it.
The bigger picture
Passwordless login is real progress, but it shifts the target from your password to your device — meaning antivirus, patching, and limiting admin rights matter just as much in a passkey world as they did in a password one. — The First Line of Defense in Employee Data Misuse
Curious whether your team’s devices are locked down enough to trust with passwordless logins? Book a free consult — https://micro1tech.com/contact/