Researchers demonstrated attack paths against Google’s synced passkey setup, showing that the weak point may be the device, browser, or recovery layer around the credential rather than WebAuthn itself.
The risk is no longer just phishing: on a compromised Windows machine, synced passkeys can become part of the attacker’s path to account takeover.
A new passkey attack write-up points to a harder truth about passwordless security: if the Windows endpoint is compromised, synced credentials can become part of the attacker’s path.