Unit 42's three Pass-ta-key attacks need malware already on Windows, no admin rights. The SDS master key sits in Chrome memory in plaintext, with no way to rotate it.
W3C WebAuthn L3 co-editor Tim Cappalli warns against deriving encryption keys from the passkey PRF extension. Why the data becomes permanently unrecoverable, how Bitwarden and WhatsApp handle it, and the envelope-encryption pattern to use instead.