Pass-ta-key tricks a PC into posing as an iPhone.

The exploit needs malware already running on the victim’s device, limiting real-world risk.

It extracts passkeys synced through Google Password Manager, then replays them as if from an iPhone.

FIDO specifications never required hardware-bound storage, leaving platforms free to close the gap or not.

Sources: Ars Technica