Are passkeys still safe after Pass-ta-key?

Unit 42 published three Pass-ta-key variants on 3 August 2026, not four as several outlets reported, all scoped to Chrome on Windows with a TPM using Google Password Manager.

Every variant requires malware already running on the device, so this is a post-compromise weakness rather than a flaw in WebAuthn or FIDO2.

macOS, Android, iOS, Apple iCloud Keychain and 1Password were not tested, which is not the same as being unaffected; a hardware security key defeats all three variants.

Read the full post

Read the full post