Passkey attestations and non-exportable private keys enable potential vendor, employer, and government lock-in via hardware whitelisting and ecosystem constraints.
Gmail was not subject to a widespread breach; protections remain strong, though phishing and vishing risk increased after a Salesforce-related incident.
Unpacking Passkeys Pwned: Possibly the most specious research in decades
Malicious browser extensions can create attacker-controlled passkeys bound to legitimate domains, allowing account takeover and undermining the perceived theft immunity of passkeys.