HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Google “Pass‑ta‑key” Attack Exposes Synchronized Passkeys Across User Devices

Researchers revealed a “Pass‑ta‑key” attack that can steal synchronized passkeys from Google Password Manager, potentially compromising user credentials. This highlights gaps in SOC 2 access‑control practices and the need for continuous evidence of credential protection.

LiveThreat™ Intelligence · 📅 August 11, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
malwarebytes.com

Google “Pass‑ta‑key” Attack Exposes Synchronized Passkeys Across User Devices

What Happened — Researchers disclosed a new “Pass‑ta‑key” attack that can extract synchronized passkeys stored in Google Password Manager. By exploiting the way Google syncs passkeys across devices, an adversary with limited access can harvest credentials for services that rely on passkey authentication.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a gap in SOC 2 Access Controls (CC6.1 – logical access management) where credential storage and synchronization must be continuously monitored and protected.
  • Highlights the need for defensible audit evidence showing that credential‑related controls (e.g., MFA enforcement, passkey rotation, privileged‑account monitoring) are operating effectively.
  • Aligns with Verisq’s SOC2 Access Controls capability, which provides continuous evidence collection and control‑mapping to prove that access‑management policies are enforced across all user devices.

Who Is Affected — Cloud‑based SaaS providers, enterprise users of Google services, and any organization that relies on passkey authentication for privileged or customer‑facing applications.

Recommended Actions

  • Conduct an immediate review of passkey provisioning and synchronization policies; enforce MFA for all accounts with passkey access.
  • Rotate any passkeys that may have been synced before the vulnerability disclosure.
  • Implement continuous monitoring of credential‑access logs and integrate alerts for anomalous extraction attempts.
  • Map the incident to SOC 2 CC6.1 controls and collect evidence of remediation for audit readiness.

Technical Notes — The attack leverages a flaw in the synchronization protocol of Google Password Manager, allowing a malicious app or compromised device to request and retrieve encrypted passkey blobs. No public CVE has been assigned yet; Google is investigating and may release a patch. Source: Malwarebytes Labs, “A week in security (August 3 – August 9)”

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-august-3-august-9

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →