San FranciscoPass-ta-key tricks a PC into posing as an iPhone.
The exploit needs malware already running on the victim’s device, limiting real-world risk.
It extracts passkeys synced through Google Password Manager, then replays them as if from an iPhone.
FIDO specifications never required hardware-bound storage, leaving platforms free to close the gap or not.
Sources: Ars Technica