Google “Pass‑ta‑key” Attack Exposes Synchronized Passkeys Across User Devices
What Happened — Researchers disclosed a new “Pass‑ta‑key” attack that can extract synchronized passkeys stored in Google Password Manager. By exploiting the way Google syncs passkeys across devices, an adversary with limited access can harvest credentials for services that rely on passkey authentication.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a gap in SOC 2 Access Controls (CC6.1 – logical access management) where credential storage and synchronization must be continuously monitored and protected.
- Highlights the need for defensible audit evidence showing that credential‑related controls (e.g., MFA enforcement, passkey rotation, privileged‑account monitoring) are operating effectively.
- Aligns with Verisq’s SOC2 Access Controls capability, which provides continuous evidence collection and control‑mapping to prove that access‑management policies are enforced across all user devices.
Who Is Affected — Cloud‑based SaaS providers, enterprise users of Google services, and any organization that relies on passkey authentication for privileged or customer‑facing applications.
Recommended Actions
- Conduct an immediate review of passkey provisioning and synchronization policies; enforce MFA for all accounts with passkey access.
- Rotate any passkeys that may have been synced before the vulnerability disclosure.
- Implement continuous monitoring of credential‑access logs and integrate alerts for anomalous extraction attempts.
- Map the incident to SOC 2 CC6.1 controls and collect evidence of remediation for audit readiness.
Technical Notes — The attack leverages a flaw in the synchronization protocol of Google Password Manager, allowing a malicious app or compromised device to request and retrieve encrypted passkey blobs. No public CVE has been assigned yet; Google is investigating and may release a patch. Source: Malwarebytes Labs, “A week in security (August 3 – August 9)”