In at least Apple's case, Device PIN is also a factor to unlock the secure enclave where the passkeys are kept - so, assuming there's no stronger enforcement that it must use FaceID/TouchID, shoulder surfing a PIN unlock of the device and then swiping it grants access to all accounts.