Your passkey isn't broken — the master key gets copied
On 3 August, Unit 42 published three ways into passkey-protected accounts without breaking a single line of cryptography. The worst of them lifts a 32-byte secret out of Chrome's memory that decrypts every passkey synced to the account — and in Google's current implementation that secret cannot be rotated or revoked. All three start the same way: with malware already running on a Windows machine, with no administrator rights and no privilege escalation. We still recommend passkeys, and this post explains why that is not a contradiction.