These are endpoint malware attacks, not attacks on Passkeys per se. This is already a game-over position for an attacker to be in.
Yes, there's no security bug here of any kind. The "novel attack surface" already assumes the attacker can execute code as your user.
Yes, there's no security bug here of any kind. The "novel attack surface" already assumes the attacker can execute code as your user.