Passkey security vulnerabilities can be exploited by attackers to gain control of accounts, according to a report by Palo Alto Networks Unit 421. The issues stem from weaknesses in the processes surrounding passkey implementation, rather than flaws in the underlying cryptography. Specifically, attackers can target onboarding flows and recovery procedures to bypass passkey protections. This is particularly concerning given the widespread adoption of passkeys in enterprise settings, where they are often used as a replacement for traditional passwords. The demonstrated attacks require a successful intrusion, but once inside, attackers can exploit these vulnerabilities to take over accounts. This matters to security practitioners because it highlights the need to carefully evaluate and secure the entire passkey ecosystem, not just the cryptographic components, to prevent account takeover attacks.