If you are blanket accepting permissions passkeys do nothing to fix the attack you describe (on device phishing).