Researchers demonstrated attack paths against Google’s synced passkey setup, showing that the weak point may be the device, browser, or recovery layer around the credential rather than WebAuthn itself.