Researchers at Palo Alto Networks’ Unit 42 have identified three attacks against Google Password Manager’s synced passkeys on Windows, highlighting implementation risks in cloud-synchronized passkeys rather than weaknesses in passkey cryptography. Unit 42 says the attacks exploit Google’s device trust, onboarding, and cloud authenticator implementation. Unit 42 found different outcomes among the services tested. Google removed the value from those logs after Unit 42 reported the issue. Unit 42 says the findings expose gaps between the security assumptions around passkeys and their implementation.