Synced Passkeys Lose Their Edge on Compromised Endpoints

A passkey only stays phishing-resistant if the endpoint stays trustworthy. Once malware controls the desktop, the trust steps meant to restore or enroll a device can be abused to make a compromised machine look approved and hand over synced private keys without a fresh user prompt. Palo Alto Networks’ Unit 42 says its research on Google’s synced passkey ecosystem and Cloud Authenticator shows account takeover paths that bypass user verification and extract all synced passkey private keys. The report ties the issue to onboarding, recovery, and device-trust workflows on desktop clients, which turns one infected endpoint into a path to every account tied to those synced passkeys. The broader risk is that passwordless deployments can still collapse back into account takeover when the synced key store itself becomes the target. That changes the threat model for passkeys beyond Google’s products, because the break is in the trust model around the device, not in password cracking or phishing.

Part of the PlainSec briefing for 2026-08-03

Every edition of this story: Synced Passkeys Lose Their Edge on Compromised Endpoints

Sources