Palo Alto Networks Unit 42发布了关于Google同步Passkey生态系统的安全研究,揭示了三种可被恶意软件利用的攻击方式[1]。这些攻击能够在已被感染的设备上绕过用户验证,使攻击者无需用户交互即可接管Passkey保护的账户[1]。
三类攻击分别为Pass-ta-key、Silver Pass-ta-key和Golden Pass-ta-key[1]。其中,Pass-ta-key攻击允许恶意软件在受害者设备上无需提权、解锁或用户操作的情况下直接接管Google同步Passkey保护的账户[1]。Silver Pass-ta-key攻击则通过欺骗Google Cloud Authenticator的方式,使攻击者能够在未使用受害者设备的情况下完整接管账户[1]。Golden Pass-ta-key攻击最具威胁性,允许攻击者提取所有同步Passkey,这些密钥随后可在凭证黑市上共享或出售[1]。
研究发现的关键漏洞包括:Cloud Authenticator在注册新设备密钥时不验证证明[1],以及安全域密钥(SDS)在Chrome进程内存中以明文形式临时存在[1]。此外,当用户验证标志设置为"preferred"而非"required"时,许多依赖方未能正确验证该标志,导致了单因素认证的风险[1]。这些攻击针对Windows Chrome中配备可信平台模块(TPM)的设备上的Google Password Manager[1],但所有攻击都以恶意软件已存在于受害者设备上为前提条件[1]。
Palo Alto Networks Unit 42 has unveiled a security analysis of Google's synchronized passkey ecosystem, identifying three novel attack vectors that enable malware to compromise accounts protected by passkeys without requiring user interaction or elevated privileges [1]. The attacks—dubbed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—exploit vulnerabilities in device trust workflows and recovery processes to hijack accounts and extract synchronized passkey private keys [1].
The Pass-ta-key attack allows malware on a compromised endpoint to take over Google synchronized passkey-protected accounts without the need for device unlocking or user consent [1]. In the Silver Pass-ta-key variant, attackers can deceive Google Cloud Authenticator to achieve complete account takeover without physical access to the victim's device [1]. The most severe variant, Golden Pass-ta-key, enables attackers to exfiltrate all synchronized passkeys, facilitating their distribution or sale on credential marketplaces [1].
These attacks exploit critical weaknesses, including Cloud Authenticator's failure to validate attestation during new device key registration and the temporary plaintext storage of Secure Domain Secrets (SDS) in Chrome process memory [1]. Additionally, when the user verification flag is set to "preferred" rather than "required," many relying parties fail to properly validate this flag, reducing authentication to a single factor [1].
The research targeted Google Password Manager on Windows Chrome devices equipped with Trusted Platform Modules [1]. All identified attack vectors require malware to be already present on the victim's device [1].