Researchers at Unit 42 have identified three attack techniques against Google Password Manager's passkey implementation in Chrome on Windows, which could allow malware already running on a victim's device to silently sign into passkey-protected accounts without any user interaction. The attacks exploit weaknesses in how Chrome stores device keys, handles device re-enrollment, and manages the 32-byte Security Domain Secret used to decrypt synced passkeys — rather than breaking the underlying cryptography. No CVEs have been assigned, the full remediation status is unclear, and it remains unknown whether actions like changing a Google Password Manager PIN would invalidate a secret an attacker has already obtained.