Pretty sure the same applies to all the passwords/passkeys/2FA codes stored in the Authenticator app with cloud backup on.
Use 1Password or similar instead. They’re keyed against a key they don’t have access to.
Only if that authenticator/password manager app is not end-to-end encrypted.
Use 1Password or similar instead. They’re keyed against a key they don’t have access to.