Trusted workflows can be misused to take over passkey-protected accounts if an attacker can first breach enterprise defenses and plant malware, researchers found; analysts say the issue is flaws in passkeys' supporting processes.

Unit 42 details three Chrome passkey attack paths that could let Windows malware bypass verification or recover synced private keys after compromise.

Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over…