Passkeys Can Be Stolen On Windows Via Google Password Manager, But The Flaw Is Narrow And Not Inherent To Passkeys
How-To Geek, Monday, August 31st, 2026
Passkeys Were Supposed to Be More Secure Than Passwords. Now They're Getting Hacked
Security researchers discovered Pass-ta-key attacks that can extract passkeys from Google Password Manager on Windows, potentially compromising accounts.
However, the vulnerability requires the device to already be compromised by malware and only affects Google's implementation, not passkey technology itself.
FIDO Alliance specifications allow passkeys to be stored locally rather than exclusively in dedicated hardware like TPMs, enabling cloud syncing but creating this specific Windows vulnerability.
Experts note passkeys remain generally secure, and users can mitigate risk by using alternative managers or hardware-based storage like Windows Hello or YubiKeys.