The attacks can misuse trusted workflows to take over passkey-protected accounts, but the attacker must have first breached defenses and planted malware; analysts say the issue is flaws in supporting processes.

Unit 42 details three Chrome passkey attack paths that could let Windows malware bypass verification or recover synced private keys after compromise.

Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over…